Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 151–225

1401 questions total · 19pages · All types, answers revealed

Page 2

Page 3 of 19

Page 4
151
Multi-Selecthard

Which TWO actions will prevent a BGP route from being installed in the routing table (RIB) while still being present in the BGP table? (Choose TWO.)

Select 3 answers
A.The route is suppressed due to an aggregate-address command.
B.The BGP next hop is unreachable via any IGP or static route.
C.The route is received with a higher local preference than the best path.
D.The neighbor is configured with 'soft-reconfiguration inbound'.
E.The route is dampened due to BGP flap dampening.
AnswersA, B, E

Correct. Aggregate-address with the 'summary-only' keyword suppresses more specific routes, keeping them in BGP but not installing them in the RIB.

Why this answer

A route is present in the BGP table but not installed in the RIB when it is suppressed by an aggregate-address command (option A), when the BGP next hop is unreachable (option B), or when it is dampened due to BGP flap dampening (option E). Dampened routes remain in the BGP table but are marked damped and are not installed. Option C is incorrect because local preference influences best-path selection but does not by itself prevent RIB installation.

Option D is incorrect because soft-reconfiguration inbound stores received updates but does not affect RIB installation.

152
MCQmedium

In a VRF-Lite setup using RIP, what is the default update timer value?

A.30 seconds
B.60 seconds
C.90 seconds
D.180 seconds
AnswerA

RIP's routing update timer defaults to 30 seconds regardless of VRF-Lite context, since VRF-Lite simply partitions the routing table without altering protocol timers. The 30-second interval therefore remains the default update value in this scenario.

Why this answer

In a VRF-Lite setup using RIP, the default update timer value is 30 seconds. This is the standard RIP update interval defined in RFC 1058 and 2453, and it remains unchanged when RIP is used within a VRF. VRF-Lite does not alter the fundamental protocol timers of RIP; it only provides logical separation of routing tables.

Therefore, the correct answer is 30 seconds.

Exam trap

The trap here is confusing the update timer with other RIP timers, such as the invalid or flush timers, which have different default values (180 and 240 seconds, respectively).

How to eliminate wrong answers

Option B is wrong because 60 seconds is not a default RIP timer; it might be confused with the flush timer or other protocol intervals. Option C is wrong because 90 seconds is not a standard RIP timer; it could be mistaken for the invalid timer in IGRP or EIGRP. Option D is wrong because 180 seconds is the default invalid timer for RIP, not the update timer; it is the time after which a route is considered invalid if no update is received.

153
MCQmedium

A network engineer runs the following command to verify NetFlow data export format: R1# show flow exporter EXPORTER-1 Flow Exporter: EXPORTER-1 Transport Configuration: Destination IP address: 192.168.1.100 Source IP address: 10.0.0.1 Transport Protocol: UDP Destination Port: 2055 Source Port: 51234 DSCP: 0x00 TTL: 255 Output Features: Used Export Protocol: NetFlow Version 9 Template Data Export Timeout: 1800 seconds Option Data Export Timeout: 1800 seconds Option Data Configured: application-table sub-application-table application-attributes What does this output indicate?

A.The exporter uses TCP to ensure reliable delivery of flow records.
B.The exporter is configured to send NetFlow version 9 data with application option data, indicating NBAR integration.
C.The exporter is not sending any option data.
D.The exporter uses a destination port of 514.
AnswerB

The output lists application-table, sub-application-table and application-attributes under Option Data Configured, alongside Export Protocol NetFlow Version 9. Those application option tables are exported by NBAR, confirming the exporter sends version 9 flow records enriched with application recognition data.

Why this answer

The output shows the configuration of a Flexible NetFlow exporter. It uses UDP to send NetFlow version 9 data to 192.168.1.100 on port 2055. It also exports option data like application tables and attributes, which are used for NBAR-based application recognition.

154
MCQmedium

A network engineer runs the following command on Router R8: R8# show logging | include %LDP-5-NBRCHG *Mar 1 00:01:10.123: %LDP-5-NBRCHG: LDP Neighbor 10.0.0.2:0 (1) is UP *Mar 1 00:02:20.456: %LDP-5-NBRCHG: LDP Neighbor 10.0.0.2:0 (1) is DOWN *Mar 1 00:03:30.789: %LDP-5-NBRCHG: LDP Neighbor 10.0.0.2:0 (1) is UP *Mar 1 00:04:40.012: %LDP-5-NBRCHG: LDP Neighbor 10.0.0.2:0 (1) is DOWN Based on this output, what is the most likely problem?

A.The LDP session is flapping due to an unstable IGP route to 10.0.0.2.
B.The MPLS label space is exhausted.
C.The router has a mismatched LDP router ID.
D.The LDP hello interval is set too high, causing slow detection.
AnswerA

LDP neighbour adjacencies depend on a stable route to the peer's transport address. Repeated UP/DOWN transitions for 10.0.0.2 indicate the underlying IGP route is flapping, tearing down and rebuilding the TCP session each time the route changes.

Why this answer

The log shows the LDP neighbor 10.0.0.2 repeatedly going UP and DOWN, which indicates a flapping LDP session. The most likely cause is an unstable IGP route to the neighbor's loopback address (used for LDP router ID), causing the LDP session to reset. LDP relies on the underlying IGP for reachability; if the route flaps, the LDP session will flap.

Exam trap

300-410 often tests the misconception that LDP session flapping is caused by LDP configuration issues, but it is frequently due to underlying IGP instability.

How to eliminate wrong answers

Option A is correct. Option B is wrong because label space exhaustion would typically cause new label bindings to fail, not the session itself to flap. Option C is wrong because a mismatched LDP router ID would prevent the session from coming up at all, not cause it to flap.

Option D is wrong because a high hello interval would delay detection of failures but would not cause repeated UP/DOWN messages; it would more likely cause slower convergence.

155
Drag & Dropmedium

Drag and drop the steps to create and register an EEM applet for syslog events into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order begins with entering global configuration mode, then defining the EEM applet and its syslog trigger, followed by configuring the action to execute, and finally exiting configuration mode to register the applet.

156
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip dhcp conflict IP address Detection method Detection time VRF 192.168.1.20 Ping Mar 01 2020 01:00 AM 192.168.1.21 Gratuitous ARP Mar 01 2020 01:05 AM Based on this output, what is the problem?

A.The DHCP server is working normally; conflicts are automatically resolved.
B.The DHCP server has detected IP address conflicts, meaning another device on the network is using the same IP addresses.
C.The DHCP server is not responding to client requests.
D.The DHCP pool is misconfigured with overlapping subnets.
AnswerB

The output lists addresses the DHCP server marked as conflicted after ping or gratuitous ARP probes received replies. This indicates duplicate IP addresses exist on the subnet, so the server withholds those addresses from its pool.

Why this answer

The `show ip dhcp conflict` command displays IP addresses that the DHCP server has detected as already in use on the network. The detection methods (Ping and Gratuitous ARP) confirm that another device is responding to these addresses, indicating a conflict. This output directly shows that the DHCP server is functioning but has identified conflicts, meaning another host is using the same IP addresses.

Exam trap

Cisco often tests the distinction between a DHCP server that is working but detecting conflicts versus a server that is failing to respond or misconfigured, leading candidates to incorrectly assume the server is broken when it is actually performing its conflict detection duties correctly.

How to eliminate wrong answers

Option A is wrong because conflicts are not automatically resolved; the DHCP server logs them and will not lease those addresses until the conflict is cleared manually or via timeout. Option C is wrong because the output shows the DHCP server is actively detecting conflicts, which requires it to be responding to client requests and performing conflict detection. Option D is wrong because overlapping subnets would cause pool exhaustion or misallocation, but the output specifically shows address conflicts detected via Ping and ARP, not a pool configuration issue.

157
MCQeasy

What is the default port number used by syslog servers to receive UDP syslog messages?

A.UDP 162
B.UDP 514
C.TCP 514
D.UDP 161
AnswerB

Syslog servers listen on UDP port 514 by default, as defined in RFC 3164, so this satisfies the stem's requirement for the standard UDP syslog reception port. No configuration change is needed for default operation, unlike TCP 1468 or encrypted alternatives such as 6514.

Why this answer

RFC 5424 and the traditional BSD syslog implementation define UDP port 514 as the standard port for receiving syslog messages. Most network devices and syslog daemons default to sending and listening on UDP 514, making it the correct answer. TCP 514 is used for rsh, not syslog, and UDP 162/161 belong to SNMP.

Exam trap

The trap here is confusing syslog's UDP 514 with TCP 514 (rsh) or with SNMP ports 161/162; candidates who memorize only '514' without the protocol pick the wrong transport.

How to eliminate wrong answers

Option A is wrong because UDP 162 is the SNMP trap receiver port, not syslog. Option C is wrong because TCP 514 is assigned to the rsh (remote shell) service, not syslog; syslog over TCP uses port 601 or a configurable port. Option D is wrong because UDP 161 is the SNMP agent query port, unrelated to syslog.

158
Drag & Dropmedium

Drag and drop the steps to negotiate an IKEv2 IPsec site-to-site tunnel into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

IKEv2 negotiation begins with Phase 1 (IKE_SA_INIT) to establish a secure channel, followed by IKE_AUTH to authenticate and exchange identities. Phase 2 (CREATE_CHILD_SA) then negotiates the IPsec SA, and the final step installs the IPsec security associations into the data plane.

159
Multi-Selecthard

A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to ensure that CoPP policies are applied correctly and that the router's control plane is protected. Which two statements about CoPP configuration are true? (Choose two.)

Select 2 answers
A.CoPP policies are applied globally to all interfaces using the service-policy command in global configuration mode.
B.CoPP policies are applied to the data plane to filter transit traffic.
C.CoPP can be configured to rate-limit specific types of traffic, such as OSPF and SSH, to protect the route processor.
D.CoPP uses a modular QoS CLI (MQC) framework with class maps and policy maps to classify and police control plane traffic.
E.CoPP requires that all control plane traffic be explicitly permitted in a class map, otherwise it is dropped by default.
AnswersC, D

CoPP allows the creation of class maps that match specific protocols or ports, such as OSPF or SSH, and policy maps that apply rate limiting (policing) to those classes. This protects the route processor from being overwhelmed by excessive control plane traffic. This statement is accurate.

Why this answer

CoPP uses the MQC framework to classify and police control plane traffic, allowing rate limiting of specific protocols like OSPF and SSH to protect the route processor. The policy is applied to the control plane, not globally or to the data plane. Unmatched traffic is not dropped by default; a class-default can be configured to manage it.

Therefore, the true statements are that CoPP uses MQC with class maps and policy maps, and that it can rate-limit specific traffic types.

Exam trap

The trap here is thinking that CoPP automatically drops all unmatched traffic, but actually it permits it unless a class-default with a police action is configured.

160
MCQmedium

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 BGP_Neighbor_Down R1# show bgp summary BGP router identifier 10.0.0.1, local AS number 65001 BGP table version is 1, main routing table version 1 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.1.2 4 65002 5 5 1 0 0 00:02:00 Established Based on this output, which statement is correct?

A.The BGP neighbor is down.
B.The EEM policy has been triggered.
C.The BGP neighbor is up and the EEM policy has not been triggered.
D.The EEM policy is disabled.
AnswerC

The BGP summary shows the neighbour in Established state with two minutes uptime, so the session is healthy. The EEM applet BGP_Neighbor_Down triggers only on a transition away from Established, which has not occurred, so the policy remains untriggered.

Why this answer

The 'show bgp summary' output shows the neighbor 192.168.1.2 in state 'Established' with Up/Down 00:02:00, meaning the BGP session is up and stable. The EEM applet BGP_Neighbor_Down is registered but there is no evidence it has fired — the session never went down, so the trigger condition (neighbor down) was not met. Therefore the correct statement is that the neighbor is up and the EEM policy has not been triggered.

Exam trap

The trap is assuming that because an EEM policy is registered it must have triggered — candidates conflate 'registered/armed' with 'executed', but registration only means the policy is loaded and waiting for its event detector.

How to eliminate wrong answers

Option A is wrong because the State/PfxRcd column shows 'Established', which is the healthy BGP state; a down neighbor would show Idle, Active, or Connect. Option B is wrong because the EEM policy is designed to fire on neighbor-down events, and since the neighbor is Established, the trigger has not occurred. Option D is wrong because 'show event manager policy registered' explicitly lists the applet as registered, meaning it is loaded and active, not disabled.

161
MCQhard

An engineer configures an RSPAN session on a Cisco switch to monitor traffic from VLAN 30 and send it to a remote switch. The engineer creates RSPAN VLAN 200 on both switches and configures the trunk to allow VLAN 200. On the remote switch, the engineer configures the destination port as GigabitEthernet0/4 in VLAN 200. The engineer notices that the destination port is forwarding traffic, but the traffic is not from the source VLAN 30; instead, it is broadcast traffic from other VLANs. What is the most likely cause?

A.The RSPAN VLAN is also being used for other VLAN traffic due to misconfiguration.
B.The source VLAN is not configured correctly on the source switch.
C.The destination port is in the wrong VLAN.
D.The trunk is not pruning VLAN 200 correctly.
AnswerA

An RSPAN VLAN must be dedicated; if ordinary VLAN traffic is bridged into it, the destination port receives that broadcast traffic instead of only mirrored source traffic. The RSPAN VLAN 200 is carrying other VLAN traffic.

Why this answer

The RSPAN VLAN (200) is a dedicated transport VLAN that must not carry any regular user or broadcast traffic. If VLAN 200 is also assigned to access ports or allowed on trunks carrying other VLANs, the destination monitor port will receive that unrelated traffic instead of only the mirrored source VLAN 30 traffic. The symptom described — destination port forwarding broadcast traffic from other VLANs — is the classic sign that the RSPAN VLAN is being shared with production traffic.

Exam trap

The trap here is assuming RSPAN issues are always about trunk pruning or source VLAN configuration; the exam instead tests whether you know the RSPAN VLAN must be a dedicated, unused VLAN — a subtle design rule that causes 'extra' traffic on the monitor port.

How to eliminate wrong answers

Option B is wrong because if the source VLAN were misconfigured, no traffic (or the wrong source traffic) would be mirrored at all, but the question states the destination port is forwarding traffic — just the wrong kind. Option C is wrong because the destination port is correctly placed in VLAN 200; putting it in another VLAN would break RSPAN entirely, not cause leakage of other VLAN broadcasts. Option D is wrong because VLAN pruning on the trunk would prevent VLAN 200 from traversing the trunk, which would stop RSPAN traffic altogether rather than allow extra broadcast traffic to appear.

162
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip sla statistics IPSLAs Latest Statistics: Round Trip Time (RTT) for Index 1 Latest RTT: 10 ms Latest RTT (milliseconds): 10 Number of successes: 100 Number of failures: 0 Operation time to live: 3000 Operation frequency: 60 seconds Next operation start time: 00:00:45 Based on this output, what is the status of the IP SLA operation?

A.The IP SLA operation has failed 100 times.
B.The IP SLA operation is successful and has a low RTT.
C.The IP SLA operation is not configured correctly.
D.The IP SLA operation is about to expire.
AnswerB

One hundred successes with zero failures confirms the operation completes reliably, and a 10 ms latest RTT sits well below any typical threshold, indicating healthy low-latency reachability. The 60-second frequency and pending next operation show the probe continues running normally.

Why this answer

The output shows 100 successes and 0 failures, with a latest RTT of 10 ms, indicating the IP SLA operation is functioning correctly and with low latency. The 'Number of successes: 100' confirms the operation has been consistently successful, and the low RTT value reflects good network performance.

Exam trap

Cisco often tests the misinterpretation of 'Number of successes' versus 'Number of failures', leading candidates to confuse the count of successes with failures, especially when the numbers are large.

How to eliminate wrong answers

Option A is wrong because the output clearly states 'Number of failures: 0', not 100; the 100 refers to successes, not failures. Option C is wrong because the operation is configured correctly, as evidenced by the successful probes, valid frequency (60 seconds), and time-to-live (3000 seconds). Option D is wrong because the 'Operation time to live: 3000' indicates the operation will remain active for 3000 seconds (50 minutes) from its start, and the 'Next operation start time: 00:00:45' shows it is scheduled to run again in 45 seconds, not about to expire.

163
MCQhard

A network engineer runs the following command to troubleshoot SNMPv3 group configuration: R1# show snmp group group name: admin-group security model: v3 auth priv read view: v1default write view: v1default notify view: v1default Group name: monitor-group security model: v3 auth no priv read view: v1default write view: none notify view: v1default What does this output indicate?

A.The 'admin-group' requires authentication and encryption, while 'monitor-group' requires only authentication.
B.Both groups require authentication and encryption.
C.The 'monitor-group' has read-write access.
D.The groups use SNMPv2c security model.
AnswerA

The security model field confirms admin-group enforces authPriv, meaning both authentication and encryption, whereas monitor-group uses authNoPriv, requiring authentication without encryption. This directly satisfies the stem's constraint of distinguishing SNMPv3 security levels per group, showing monitor-group also lacks write access via its none write view.

Why this answer

The output shows that 'admin-group' uses security model 'v3 auth priv', which requires both authentication and encryption (privacy). 'monitor-group' uses 'v3 auth no priv', which requires authentication but no encryption. This matches option A exactly.

Exam trap

Cisco often tests the distinction between 'auth priv' and 'auth no priv' by presenting output where candidates mistakenly assume both groups require encryption, or confuse 'write view: none' with having write access.

How to eliminate wrong answers

Option B is wrong because 'monitor-group' uses 'auth no priv', not 'auth priv', so it does not require encryption. Option C is wrong because 'monitor-group' has 'write view: none', meaning it has no write access, only read access. Option D is wrong because both groups explicitly use 'v3' security model, which is SNMPv3, not SNMPv2c.

164
MCQhard

A network engineer runs the following command to troubleshoot an ERSPAN issue: R1# show monitor session 6 detail Session 6 --------- Type : ERSPAN Source Session Source VLANs : Both : 10-20 Destination IP : 10.1.1.3 ERSPAN ID : 200 What does this output indicate?

A.The session is correctly configured to monitor VLANs 10 through 20.
B.The session is misconfigured because ERSPAN cannot use VLANs as source.
C.The session is misconfigured because the ERSPAN ID must be less than 100.
D.The session is misconfigured because the destination IP must be on the same subnet.
AnswerA

Monitoring both VLANs 10–20 satisfies the source specification, and the destination IP plus ERSPAN ID confirm the session is fully defined. Because ERSPAN encapsulates mirrored traffic in GRE for routed transport, the source session needs no local destination interface — so this output shows a valid, complete configuration.

Why this answer

The output shows an ERSPAN source session with source VLANs 10-20, destination IP 10.1.1.3, and ERSPAN ID 200. This is a valid ERSPAN source session using VLANs as the source.

165
MCQeasy

A network engineer runs the following command on Router PE5: PE5# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.0.0.7 1 FULL/DR 00:00:32 10.1.1.7 GigabitEthernet0/0 10.0.0.8 1 FULL/BDR 00:00:35 10.2.2.8 GigabitEthernet0/1 Based on this output, which statement is correct?

A.Both OSPF adjacencies are fully established.
B.One neighbor is in the EXSTART state.
C.The router is not the DR for any segment.
D.There is a mismatch in OSPF area IDs.
AnswerA

The State column shows FULL for both neighbours, meaning the link-state databases have synchronised and adjacency is complete. The /DR and /BDR suffixes only denote designated router roles on their respective segments, not incomplete adjacency.

Why this answer

The State column shows FULL/DR for neighbor 10.0.0.7 and FULL/BDR for 10.0.0.8. FULL means the link-state databases are synchronized and the adjacency is fully established on both segments. The DR/BDR roles are normal on a broadcast segment and do not indicate a problem.

Exam trap

The trap is misreading the State column: candidates see DR/BDR and think it indicates a problem, when FULL/DR and FULL/BDR are the healthy, expected states on a broadcast segment.

How to eliminate wrong answers

Option B is wrong because EXSTART is a transient OSPF neighbor state during database exchange; the output shows FULL, which is the final and stable state. Option C is wrong because the router PE5 is the DR on the segment where the neighbor is BDR (10.0.0.8 is BDR, so PE5 must be DR on that segment), so the statement that PE5 is not DR for any segment is false. Option D is wrong because an area ID mismatch would prevent the adjacency from reaching FULL — the neighbor would be stuck in DOWN or INIT, and the output shows FULL for both.

166
MCQmedium

A network engineer is configuring a Cisco IOS XE router to connect to an ISP via BGP. The engineer wants to influence inbound traffic from the ISP by prepending the router's AS number multiple times to the BGP updates sent to the ISP. Which BGP attribute should the engineer modify to achieve this?

A.Weight
B.AS path
C.Multi-exit discriminator (MED)
D.Local preference
AnswerB

AS path is a well-known mandatory attribute that lists the autonomous systems a route has traversed. By prepending additional AS numbers to the AS path, the engineer makes the route appear longer, which is less preferred by BGP. This influences inbound traffic because the ISP will choose a shorter AS path if available. It is a common method to manipulate inbound traffic.

Why this answer

AS path prepending is the technique of adding multiple instances of the local AS number to the AS path attribute in BGP updates sent to external peers. This makes the route less attractive because a longer AS path is less preferred. It is a standard method to influence inbound traffic from an ISP.

Local preference and weight affect outbound traffic, while MED is an alternative but less forceful method for inbound influence.

Exam trap

The trap here is confusing attributes that influence outbound traffic (local preference, weight) with those that influence inbound traffic (AS path, MED).

167
MCQhard

An engineer configures mutual redistribution between EIGRP and OSPF on a router. EIGRP routes are redistributed into OSPF with a route-map that sets metric-type type-1, and OSPF routes are redistributed into EIGRP with default metric 10000 100 255 1 1500. Unexpectedly, the router starts flapping routes between the two protocols, causing instability. Which is the most likely explanation?

A.The redistribution is not using route tags, so routes are being re-redistributed back and forth, causing route flapping.
B.The OSPF metric-type type-1 is incompatible with EIGRP, causing the route to be rejected.
C.The EIGRP default metric is missing the reliability and load values, so redistribution fails.
D.The router must have `redistribute connected` under both protocols to avoid flapping.
AnswerA

Without route tags, each protocol re-advertises the other's routes back, creating a mutual redistribution loop. The stem's flapping stems from this feedback: EIGRP-learned routes return via OSPF and vice versa. Tagging redistributed routes and denying tagged routes on the reciprocal redistribution breaks the cycle.

Why this answer

Mutual redistribution without route tagging causes routes to be redistributed back and forth between EIGRP and OSPF, creating a feedback loop. A route learned from OSPF is redistributed into EIGRP, then learned back from EIGRP into OSPF, and so on, causing the route to flap as metrics and path attributes change. Route tags are the standard mechanism to prevent this by marking routes with a tag on redistribution and denying routes with that tag on the reverse redistribution.

Exam trap

300-410 often tests the misconception that mutual redistribution works without loop prevention; candidates may blame metric incompatibility or missing parameters instead of recognizing the need for route tags to break the redistribution feedback loop.

How to eliminate wrong answers

Option B is wrong because OSPF metric-type type-1 (E1) is fully compatible with redistribution into EIGRP; EIGRP uses its own metric parameters and does not reject OSPF E1 routes based on metric type. Option C is wrong because the EIGRP default metric '10000 100 255 1 1500' includes bandwidth, delay, reliability, load, and MTU—all five parameters are present, so redistribution will not fail for missing values. Option D is wrong because 'redistribute connected' is unrelated to preventing mutual redistribution loops; it would actually add more routes and potentially worsen the issue.

168
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 bgp summary BGP router identifier 192.168.1.1, local AS number 65001 BGP table version is 10, main routing table version 10 5 network entries using 720 bytes of memory 5 path entries using 400 bytes of memory 3/2 BGP path/bestpath attribute entries using 456 bytes of memory 1 BGP AS-PATH entries using 24 bytes of memory 0 BGP route-map cache entries using 0 bytes of memory 0 BGP filter-list cache entries using 0 bytes of memory BGP using 1600 total bytes of memory BGP activity 10/5 prefixes, 10/5 paths, scan interval 60 secs Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 2001:DB8::2 4 65002 100 99 10 0 0 00:45:12 3 Based on this output, which statement is correct?

A.BGP is not configured for IPv6.
B.The BGP session is down.
C.BGP is peering over IPv6 and 3 prefixes are learned from the neighbor.
D.The router is in AS 65002.
AnswerC

The neighbor line shows an IPv6 address (2001:DB8::2), confirming the session runs over IPv6, and the State/PfxRcd column reads 3, meaning three prefixes were accepted from that peer. Both facts come straight from the summary output.

Why this answer

The output shows that the neighbor 2001:DB8::2 (IPv6 address) is in state '3' under 'State/PfxRcd', which indicates the BGP session is established and 3 IPv6 prefixes have been received from that neighbor. The 'Up/Down' time of 00:45:12 confirms the session is active, and the 'MsgRcvd/MsgSent' counters show bidirectional communication. Therefore, BGP is peering over IPv6 and has learned 3 prefixes from the neighbor, making option C correct.

Exam trap

Cisco often tests the interpretation of the 'State/PfxRcd' column in 'show bgp ipv6 unicast summary' (or 'show ipv6 bgp summary'), where a numeric value indicates an established session and received prefixes, while a state name indicates a session problem, leading candidates to mistakenly think the session is down when they see a number instead of a state.

How to eliminate wrong answers

Option A is wrong because the command 'show ipv6 bgp summary' explicitly displays IPv6 BGP information, and the neighbor is an IPv6 address (2001:DB8::2), proving BGP is configured for IPv6. Option B is wrong because the 'State/PfxRcd' column shows '3' (not an idle/active/connect state), and the 'Up/Down' timer is 00:45:12, indicating the session is up and exchanging prefixes. Option D is wrong because the output clearly states 'local AS number 65001' in the BGP router identifier line, and the neighbor AS is 65002; the router is in AS 65001, not 65002.

169
MCQeasy

A network engineer runs the following command on Router R1: R1# show flow interface GigabitEthernet0/1 Interface GigabitEthernet0/1 FNF: monitor Monitor: FLOW-MONITOR-1 direction: Input traffic-statistics: enabled Based on this output, what can be concluded?

A.The flow monitor is applied only to incoming traffic on this interface.
B.The flow monitor is applied to both input and output traffic.
C.Traffic statistics are disabled.
D.The flow monitor is not attached to any interface.
AnswerA

The direction field shows Input, meaning Flexible NetFlow captures only packets entering GigabitEthernet0/1. No output direction is listed, so egress traffic on that interface is not monitored by FLOW-MONITOR-1, satisfying the question's constraint about which traffic is sampled.

Why this answer

The output shows that flow monitor FLOW-MONITOR-1 is applied to GigabitEthernet0/1 in the input direction with traffic statistics enabled.

170
MCQeasy

What is the default behavior of a local SPAN session if no direction (rx, tx, both) is specified?

A.Only ingress traffic is monitored.
B.Only egress traffic is monitored.
C.Both ingress and egress traffic are monitored.
D.No traffic is monitored until direction is explicitly set.
AnswerC

Cisco IOS defaults a local SPAN session to monitor both directions when no keyword is given, so ingress and egress frames on the source interface are copied to the destination port. Specifying rx or tx narrows this; omitting direction satisfies the stem's default-behaviour constraint.

Why this answer

In a local SPAN session, if no direction is specified, the default is to monitor both ingress and egress traffic. This means that all traffic entering and leaving the source interface is copied to the destination interface. The direction keyword is optional and defaults to `both`.

Exam trap

The trap here is assuming that no direction means no traffic or only one direction. Candidates might think that explicit configuration is required, but the default is both.

How to eliminate wrong answers

Option A is wrong because ingress-only monitoring requires the `rx` keyword. Option B is wrong because egress-only monitoring requires the `tx` keyword. Option D is wrong because the session does not require explicit direction; it defaults to both.

171
MCQmedium

A network engineer runs the following command on Router R1: R1# show flow exporter EXPORTER-1 statistics Flow Exporter: EXPORTER-1 Packet send statistics (last 30 seconds): Packets sent: 0 Packets dropped: 0 Packets unsent: 0 Client send statistics: Packets sent: 0 Packets dropped: 0 Packets unsent: 0 Export statistics: Number of Flows exported: 0 Number of Packets exported: 0 Number of Source IP address unreachable: 0 Number of Packets dropped (no route): 0 Number of Packets dropped (queue full): 0 Based on this output, what is the most likely cause of no exports?

A.The destination IP address is unreachable.
B.The flow exporter is not referenced in any flow monitor, or the flow monitor is not attached to an interface.
C.The UDP port is blocked by a firewall.
D.The source IP address is not configured on any interface.
AnswerB

All counters are zero, including flows exported and packets dropped, indicating the exporter is never invoked. That happens when no flow monitor references it, or the monitor is not applied to an interface, so no flow data reaches the export process.

Why this answer

The output shows zero packets sent, zero dropped, and zero unsent across all statistics, with no errors like unreachable destination or no route. This indicates the exporter is not being invoked at all, which typically means the flow exporter is not referenced by any flow monitor, or the flow monitor is not attached to an interface. Without that binding, no flows are exported.

Exam trap

300-410 often tests whether candidates can distinguish between configuration binding issues and network reachability issues — the trap is assuming a zero-packet count means a network problem, when it actually means the exporter is not being called.

How to eliminate wrong answers

Option A is wrong because the output shows 'Number of Source IP address unreachable: 0' and 'Number of Packets dropped (no route): 0', indicating no reachability errors. Option C is wrong because a firewall blocking UDP would typically show packets sent but dropped, or unsent packets, not all zeros. Option D is wrong because a missing source IP would likely cause export failures or errors, and the output shows no such errors.

172
MCQhard

Which statement about administrative distance is true regarding the selection of routes in a routing table?

A.Routes with higher administrative distance are always preferred.
B.Administrative distance is only considered when metrics are equal.
C.The route with the lowest administrative distance is installed in the routing table.
D.Administrative distance is used to select the best path within the same routing protocol.
AnswerC

Administrative distance ranks route sources by trustworthiness; when multiple sources offer a path to the same prefix, the lowest value wins and is installed in the routing table. This directly satisfies the stem's selection criterion, with static routes at 1 and eBGP at 20 as examples.

Why this answer

The route with the lowest administrative distance is installed in the routing table when multiple routing protocols provide a route to the same destination. Administrative distance is a measure of trustworthiness; lower values are preferred. This is a fundamental principle in Cisco routing.

Exam trap

300-410 often tests... the difference between administrative distance and metric, and candidates might incorrectly think AD is used within the same protocol or that higher AD is preferred.

How to eliminate wrong answers

Option A is wrong because higher administrative distance is less preferred; lower is better. Option B is wrong because administrative distance is considered before metrics; metrics are only compared within the same routing protocol. Option D is wrong because administrative distance is used to select between different routing protocols, not within the same protocol; within a protocol, metrics are used.

173
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 dhcp interface Gi0/0/0 Gi0/0/0 is in server mode Uses prefix 2001:DB8:1::/64 Rapid-Commit is disabled Preference value: 0 Information refresh option: 86400 DNS server: 2001:DB8::1 Domain name: example.com Active clients: 5 Pool: DHCP_POOL Based on this output, which statement is correct?

A.The router is acting as a DHCPv6 client on Gi0/0/0.
B.The router is acting as a DHCPv6 server on Gi0/0/0 and has 5 active clients.
C.Rapid-Commit is enabled.
D.The interface is using SLAAC for address assignment.
AnswerB

The output explicitly states "Gi0/0/0 is in server mode", confirming R1 runs DHCPv6 server functions on that interface rather than relay or client mode. The "Active clients: 5" line directly reports five bound clients, satisfying the stem's requirement to identify both the operational role and current lease count.

Why this answer

The output shows Gi0/0/0 is in server mode, with a prefix, DNS server, domain name, and a pool named DHCP_POOL. The line 'Active clients: 5' confirms the router is acting as a DHCPv6 server with five active clients. This matches option B exactly.

Exam trap

Cisco often tests the distinction between DHCPv6 server mode and client mode, and the trap here is that candidates may misinterpret 'Active clients' as a client-side metric or confuse DHCPv6 server operation with SLAAC.

How to eliminate wrong answers

Option A is wrong because the interface is in server mode, not client mode; a DHCPv6 client would show 'client mode' and typically a 'client DUID'. Option C is wrong because the output explicitly states 'Rapid-Commit is disabled', not enabled. Option D is wrong because the interface is using DHCPv6 prefix delegation and address assignment (server mode), not Stateless Address Autoconfiguration (SLAAC), which relies on Router Advertisements without a DHCPv6 server.

174
MCQmedium

A network engineer runs the following command to troubleshoot IPsec on a DMVPN tunnel: R1# debug crypto isakmp ISAKMP: received peer 192.168.1.2, port 500, local 192.168.1.1 ISAKMP: SA created, initiating IKE Main Mode ISAKMP: sent MM_SA proposal to 192.168.1.2 ISAKMP: received MM_SA response from 192.168.1.2 ISAKMP: Main Mode complete, starting Quick Mode ISAKMP: sent QM_SA request to 192.168.1.2 ISAKMP: received QM_SA response from 192.168.1.2 ISAKMP: Quick Mode done, IPsec SA established What does this output indicate?

A.IKE negotiation failed; no IPsec SA was established.
B.IKE negotiation succeeded and an IPsec SA is now active.
C.The peer 192.168.1.2 is not responding to IKE requests.
D.IKE is using Aggressive Mode instead of Main Mode.
AnswerB

The debug trace shows IKE Main Mode completing, then Quick Mode exchanging proposals and completing, with the final line confirming the IPsec SA is established. Phase 1 and Phase 2 negotiation both succeeded between the peers.

Why this answer

The debug output shows that IKE Main Mode completed successfully, Quick Mode completed, and an IPsec SA was established. This indicates that the IKE negotiation succeeded and the tunnel is active.

Exam trap

The trap is that candidates might misinterpret the debug output as indicating a failure because it shows messages, but the key is to look for the final 'IPsec SA established' line, which confirms success.

How to eliminate wrong answers

Option A is wrong because the output explicitly states 'IPsec SA established', indicating success, not failure. Option C is wrong because the peer responded to IKE requests (received MM_SA response and QM_SA response), so it is responding. Option D is wrong because the output shows 'initiating IKE Main Mode' and 'Main Mode complete', so it is using Main Mode, not Aggressive Mode.

175
MCQmedium

A network engineer runs the following command on Router R1: R1# show bgp neighbors 10.1.12.2 advertised-routes BGP table version is 15, local router ID is 10.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.1.1.0/24 0.0.0.0 0 32768 i *> 10.2.2.0/24 10.1.12.2 0 0 65002 i Total number of prefixes 2 Based on this output, what can be concluded about the route 10.2.2.0/24?

A.The route 10.2.2.0/24 is being advertised back to the neighbor from which it was learned, which is incorrect.
B.The route 10.2.2.0/24 is locally originated.
C.The route 10.2.2.0/24 has a weight of 0.
D.The route 10.2.2.0/24 is not valid.
AnswerA

The output lists 10.2.2.0/24 with next hop 10.1.12.2, the same neighbour the command queries, proving R1 is advertising the prefix back to its originator. Standard BGP loop prevention should suppress this, so an outbound policy or missing inbound filter is leaking it.

Why this answer

The output shows that the route 10.2.2.0/24 has a next hop of 10.1.12.2, which is the neighbor's IP, and the path shows 65002, indicating it was learned from that neighbor. The command 'show bgp neighbors 10.1.12.2 advertised-routes' displays routes advertised to that neighbor, so this route is being advertised back to the neighbor it was learned from, which is incorrect due to BGP loop prevention (unless allowas-in is configured).

Exam trap

300-410 often tests BGP loop prevention and the interpretation of show commands, causing candidates to misread the advertised-routes output as received routes.

How to eliminate wrong answers

Option B is wrong because the route has a next hop of 10.1.12.2 and path 65002, indicating it was learned from a neighbor, not locally originated. Option C is wrong because the weight is not shown in this output; the '0' in the metric column is the MED, not weight. Option D is wrong because the route is valid (status code *>), so it is valid and best.

176
MCQhard

Router R1 and R2 are iBGP peers in the same AS. R1 learns a route 172.16.1.0/24 from an eBGP peer with AS_PATH 100 200. R2 learns the same prefix from another eBGP peer with AS_PATH 100. Both routers redistribute the route into OSPF with default administrative distance. R3, an OSPF internal router, sees two OSPF external routes for 172.16.1.0/24: one from R1 (type-5, metric 20) and one from R2 (type-5, metric 30). R3's 'show ip route 172.16.1.0' shows the route via R1. What is the root cause of R3 preferring the route via R1?

A.R3 prefers the route with the lower metric (20) over the higher metric (30), which is correct OSPF behavior.
B.R3 has a static route with AD 1 that overrides both OSPF routes.
C.The route from R1 is an OSPF inter-area route (AD 110) while from R2 is external (AD 110), so they are equal; metric decides.
D.R3's OSPF process has 'distance 150' configured, making all OSPF routes AD 150, but the route from R2 is redistributed from BGP with a lower AD.
AnswerA

OSPF selects among multiple external type-5 routes to the same prefix by comparing metric when forwarding addresses and route types match. R3 therefore installs the R1 path with metric 20, which is standard OSPF behaviour, not a fault.

Why this answer

When two OSPF external (type-5) LSAs describe the same prefix with the same forwarding metric type (both E2 by default), R3 compares the external metric carried in the LSA — 20 versus 30 — and installs the lower-metric path via R1. This is standard OSPF E2 route selection behavior, so the route via R1 is preferred purely on metric.

Exam trap

The trap is overcomplicating the scenario with administrative distance or route-type confusion — candidates may chase AD values or assume inter-area vs. external distinctions matter, when the question is simply testing that OSPF E2 external routes are selected by lowest external metric.

How to eliminate wrong answers

Option B is wrong because the scenario states R3 sees two OSPF external routes and the output shows the route via R1 — there is no mention of a static route, and a static route with AD 1 would have been shown as a static entry, not an OSPF external route. Option C is wrong because both routes are type-5 external routes (AD 110), not inter-area (AD 110 applies to OSPF but the route type is external, not inter-area), and the question already establishes they are external type-5 LSAs. Option D is wrong because changing the OSPF administrative distance to 150 affects comparison against other protocols, not the metric comparison between two OSPF external routes; the scenario explicitly says default administrative distance is used.

177
MCQmedium

A network engineer is configuring a Cisco IOS XE router to authenticate OSPFv3 neighbors. The engineer applies the following configuration under the OSPFv3 process: `area 0 authentication ipsec spi 256 sha1 0123456789ABCDEF0123456789ABCDEF01234567`. The engineer then verifies the neighbor relationship and sees that it remains in EXSTART state. Which action should the engineer take to resolve the issue?

A.Configure a key chain with the same key ID and key string on both routers.
B.Enable OSPFv3 authentication globally with the `ipv6 ospf authentication` command on all interfaces.
C.Configure the same IPsec SPI and key on the neighboring router under its OSPFv3 process.
D.Change the authentication algorithm to MD5 to match the neighbor's configuration.
AnswerC

OSPFv3 authentication uses IPsec AH or ESP with a manually configured SPI and key. Both neighbors must have matching SPI values and identical keys for the security association to be established. Without the same SPI and key on the peer, IPsec authentication fails, preventing OSPFv3 packets from being accepted and leaving the adjacency stuck in EXSTART.

Why this answer

OSPFv3 authentication uses IPsec to secure protocol packets. The configuration requires an SPI and a key to be manually set under the OSPFv3 process on both routers. When the peer lacks the matching SPI and key, authentication fails, and the adjacency cannot progress beyond EXSTART.

Configuring the identical IPsec parameters on the neighbor resolves the issue.

Exam trap

The trap here is assuming that OSPFv3 authentication can be configured per interface like OSPFv2, when it actually requires process-level IPsec parameters.

178
MCQmedium

Which IP SLA operation type is specifically designed to measure one-way delay, jitter, and packet loss using UDP packets with sequence numbers and timestamps?

A.UDP Echo
B.UDP Jitter
C.ICMP Path Echo
D.TCP Connect
AnswerB

UDP Jitter sends numbered, timestamped UDP probes in both directions, letting the responder compute per-packet one-way delay, inter-packet jitter and loss. This satisfies the stem's requirement for those three metrics over UDP, unlike ICMP echo or TCP Connect operations.

Why this answer

UDP Jitter is the IP SLA operation specifically designed to measure one-way delay, jitter, and packet loss by sending UDP packets with sequence numbers and timestamps. It is the standard operation for VoIP and real-time traffic SLA monitoring.

Exam trap

300-410 often tests the confusion between UDP Echo (basic reachability/RTT) and UDP Jitter (jitter, one-way delay, packet loss), causing candidates to pick UDP Echo for real-time traffic measurement.

How to eliminate wrong answers

Option A is wrong because UDP Echo measures round-trip time and reachability but does not provide jitter or one-way delay measurements with timestamped sequence numbers. Option C is wrong because ICMP Path Echo measures hop-by-hop round-trip latency using ICMP, not UDP jitter metrics. Option D is wrong because TCP Connect measures the time to establish a TCP session, which is unrelated to jitter and packet loss measurement.

179
MCQmedium

Examine the following partial MPLS configuration on a Cisco IOS-XE router: interface GigabitEthernet0/0 ip address 10.0.1.1 255.255.255.252 mpls ip mpls label protocol ldp ! router ospf 1 network 10.0.1.0 0.0.0.3 area 0 ! mpls ldp router-id Loopback0 force What is the effect of this configuration?

A.LDP will establish a session with the neighbor on GigabitEthernet0/0, using Loopback0 as the transport address.
B.LDP will use the IP address of GigabitEthernet0/0 as the router ID because 'force' is not valid.
C.LDP sessions will fail because OSPF is not redistributed into LDP.
D.MPLS forwarding will not occur because 'mpls label protocol ldp' is redundant and causes a conflict.
AnswerA

The 'mpls ldp router-id Loopback0 force' command forces LDP to use Loopback0 as the router ID, which becomes the transport address for LDP sessions. The 'mpls ip' on the interface enables label switching and LDP hello messages.

Why this answer

The command 'mpls ldp router-id Loopback0 force' forces LDP to use the Loopback0 interface address as the LDP router ID, which becomes the transport address for the LDP session. Because the interface has 'mpls ip' and 'mpls label protocol ldp' enabled and OSPF advertises the connected subnet, LDP will form a session with the directly connected neighbor on GigabitEthernet0/0 using that loopback-derived transport address.

Exam trap

300-410 often tests the misconception that LDP requires route redistribution or that 'force' is invalid, when in fact LDP only needs IGP reachability to the router ID and 'force' simply applies the router ID immediately.

How to eliminate wrong answers

Option B is wrong because 'force' is a valid keyword that immediately applies the Loopback0 address as the LDP router ID without waiting for session teardown/re-establishment; the interface IP is not used. Option C is wrong because LDP does not require OSPF redistribution — LDP relies on the IGP (here OSPF) only to provide reachability to the LDP router ID; redistribution of routes into LDP is not a concept. Option D is wrong because 'mpls label protocol ldp' is not redundant or conflicting; it explicitly selects LDP as the label distribution protocol on the interface (the default on most platforms, but valid and harmless).

180
MCQhard

A network engineer runs the following command to debug MPLS LDP errors: R1# debug mpls ldp errors Output: *Mar 1 00:01:23.456: LDP: Received malformed hello from 10.0.0.2 *Mar 1 00:01:23.789: LDP: Received malformed initialization from 10.0.0.2 *Mar 1 00:01:24.012: LDP: Session with 10.0.0.2:0 (0x1234) is DOWN What does this output indicate?

A.The LDP session with 10.0.0.2 failed due to malformed messages from the neighbor
B.The LDP session with 10.0.0.2 is up and stable
C.R1 is sending malformed messages to 10.0.0.2
D.The LDP session is using incorrect transport address
AnswerA

Malformed hello and initialisation messages from 10.0.0.2 prevent LDP session establishment, so the session goes DOWN. The debug output attributes the failure directly to those malformed messages received from the neighbour, confirming the session failed for that reason.

Why this answer

The debug output shows LDP errors. R1 received malformed hello and initialization messages from neighbor 10.0.0.2, causing the LDP session to go down. This indicates a configuration mismatch or software bug on the neighbor.

181
Drag & Dropmedium

Drag and drop the steps to verify and validate EEM operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Begin by displaying registered EEM policies, then check the status of each policy (active/inactive), review event history and timestamps, examine the policy actions and variables, and finally confirm the policy triggers correctly with a test event.

182
MCQmedium

A network engineer runs the following command to troubleshoot an MPLS Operations issue: R1# debug mpls ldp transport 10.1.1.1 Output: *Mar 1 00:01:23.456: LDP: Sent hello to 10.1.1.1 (UDP 646) on GigabitEthernet0/0 *Mar 1 00:01:23.789: LDP: Received hello from 10.1.1.1 (UDP 646) on GigabitEthernet0/0 *Mar 1 00:01:24.012: LDP: Opened TCP connection to 10.1.1.1:646 *Mar 1 00:01:24.345: LDP: Initialization msg sent to 10.1.1.1 *Mar 1 00:01:24.678: LDP: Initialization msg received from 10.1.1.1 *Mar 1 00:01:25.001: LDP: Session with 10.1.1.1:0 (0x1234) is UP What does this output indicate?

A.LDP session with neighbor 10.1.1.1 is successfully established
B.LDP discovery via multicast hello failed
C.TCP connection to 10.1.1.1 was refused
D.LDP session is stuck in initialization state
AnswerA

The log shows the full LDP discovery and session sequence: hello exchange over UDP 646, TCP connection, Initialization message exchange, then session state UP. That final UP state confirms the label distribution adjacency with 10.1.1.1 formed successfully.

Why this answer

The debug output shows the full LDP session establishment sequence: hello exchange over UDP 646, TCP connection to port 646, initialization message exchange, and finally 'Session ... is UP.' This confirms that the LDP session with neighbor 10.1.1.1 has been successfully established.

Exam trap

300-410 often tests whether candidates can read the LDP state machine — many see 'Initialization msg' and assume the session is stuck, missing that the subsequent 'Session ... is UP' line confirms successful establishment.

How to eliminate wrong answers

Option B is wrong because the log explicitly shows hello messages sent and received, so discovery succeeded. Option C is wrong because the log shows the TCP connection was opened successfully, not refused. Option D is wrong because the session reached the UP state, which means initialization completed and the session is operational, not stuck.

183
MCQeasy

A network administrator is configuring AAA on a Cisco IOS router. The administrator wants to authenticate administrative users against a TACACS+ server and ensure that if the TACACS+ server is unreachable, the router falls back to local authentication. The administrator has configured the TACACS+ server and local user accounts. Which additional configuration is required to achieve this?

A.Configure 'aaa authentication login default local group tacacs+'.
B.Configure 'aaa authentication login default group tacacs+ local'.
C.Configure 'aaa authentication login default group tacacs+ enable'.
D.Configure 'aaa authorization exec default group tacacs+ local'.
AnswerB

The 'aaa authentication login default group tacacs+ local' command configures the router to first attempt authentication via TACACS+ and then fall back to the local database if the TACACS+ server is unreachable. This meets the requirement for fallback authentication.

Why this answer

The correct command is 'aaa authentication login default group tacacs+ local', which specifies TACACS+ as the primary authentication method and local as the fallback. This ensures that if the TACACS+ server is unreachable, the router will use the local user database. Other options either reverse the order or use different methods that do not meet the fallback requirement.

Exam trap

The trap here is confusing the order of authentication methods or using 'enable' as a fallback instead of 'local', which does not provide local user authentication.

184
Drag & Drophard

Drag and drop the steps to troubleshoot NAT and PAT adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Troubleshooting NAT connectivity failures should start with verifying basic reachability using ping, then checking NAT translations with show ip nat translations, then examining the routing table to ensure return traffic is routed correctly, then verifying access lists for NAT, and finally checking for asymmetric routing or adjacency issues.

185
MCQmedium

Which of the following is a limitation of local SPAN on a Cisco switch?

A.It can only monitor one source interface per session.
B.The destination port must be in the same VLAN as the source.
C.It cannot mirror traffic to a remote switch.
D.It cannot monitor both ingress and egress traffic simultaneously.
AnswerC

Local SPAN replicates frames only to ports on the same physical switch, so mirrored traffic cannot traverse the network to a destination port on a remote device. Satisfying the stem's limitation, remote monitoring requires RSPAN or ERSPAN, which encapsulate mirrored traffic for transport across switches or routed boundaries.

Why this answer

Local SPAN (Switched Port Analyzer) on a Cisco switch can only mirror traffic to a destination port on the same switch — it cannot forward mirrored traffic across the network to a remote switch. Remote SPAN (RSPAN) or Encapsulated Remote SPAN (ERSPAN) is required for that. This is a fundamental limitation of local SPAN.

Exam trap

The trap is confusing local SPAN with RSPAN/ERSPAN — candidates may think local SPAN can mirror to a remote switch, but the exam tests that local SPAN is limited to the same switch, and remote mirroring requires RSPAN or ERSPAN.

How to eliminate wrong answers

Option A is wrong because local SPAN can monitor multiple source interfaces (or VLANs) in a single session on most Cisco platforms — the limitation is not one source per session. Option B is wrong because the destination port does not need to be in the same VLAN as the source; in fact, the destination port is typically dedicated to monitoring and removed from normal VLAN membership. Option D is wrong because local SPAN can monitor both ingress and egress traffic simultaneously using the 'both' keyword (or rx/tx separately) — this is a supported feature, not a limitation.

186
Multi-Selecthard

Which TWO conditions must be met for a BGP route to be considered the best path and installed in the routing table? (Choose TWO.)

Select 2 answers
A.The route must have the shortest AS_PATH length.
B.The next hop must be reachable via the routing table.
C.Synchronization must be disabled or the route must be present in the IGP.
D.The route must have the lowest MED value among all paths.
E.The route must have the lowest IGP metric to the next hop.
AnswersB, C

BGP performs a recursive lookup and only installs a path whose next hop resolves through the routing table. An unreachable next hop makes the route ineligible, so this reachability condition must be satisfied before best-path selection can install it.

Why this answer

Option B is correct because BGP performs a next-hop reachability check before a path can be considered valid and eligible for best-path selection; if the next hop cannot be resolved through the routing table (via a connected, static, or IGP-learned route), the path is not installed. Option C is correct because the BGP synchronization rule requires that a route learned from an IBGP peer must also be present in the IGP (or synchronization must be disabled) before it can be used; otherwise the route is not eligible for the routing table. Option A is not correct as a mandatory condition because AS_PATH length is only one step in the BGP best-path algorithm and is evaluated only after higher-priority checks such as weight, local preference, and locally originated routes.

Option D is not correct because MED is a lower-priority tiebreaker and is compared only among paths from the same neighboring AS, not as a universal requirement. Option E is not correct because the lowest IGP metric to the next hop is also a later tiebreaker in the best-path algorithm, not a condition that must always be met for every BGP route.

Exam trap

The trap here is confusing BGP best-path tiebreakers (AS_PATH, MED, IGP metric) with the prerequisites for a route to even be considered — candidates often pick AS_PATH length because it is the most famous BGP attribute, forgetting that next-hop reachability and synchronization gate eligibility first.

187
MCQmedium

A network engineer runs the following command to verify CoPP (Control Plane Policing) with route-maps: R1# show policy-map control-plane input class class-default Control Plane Service-policy input: CoPP Class-map: class-default (match-any) 12234 packets, 1234567 bytes 5 minute offered rate 1000 bps, drop rate 0 bps Match: any police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 12234 packets, 1234567 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop What does this output indicate?

A.The CoPP policy is dropping all traffic because the CIR is too low.
B.The CoPP policy is allowing all traffic and not dropping any packets.
C.The CoPP policy is only matching specific traffic classes.
D.The CoPP policy is not applied to the control plane.
AnswerB

Conformed packets equal total packets with exceeded and violated both zero, so every packet matched class-default is transmitted. The policy-map applies policing at 8000 bps, yet no traffic has breached it, confirming nothing is dropped.

Why this answer

The output shows the CoPP policy applied to the control plane. The class-default matches all traffic and polices it at 8000 bps. All packets have conformed and been transmitted, with no drops.

This indicates that the CoPP policy is working and not dropping any traffic.

188
Drag & Drophard

Drag and drop the steps to troubleshoot route summarization adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by verifying that the summarization router has a route to the null0 interface to prevent loops. Then, confirm that the summary route is being advertised to neighbors using show ip route. Next, check that the neighbor router receives the summary in its routing table.

After that, examine the neighbor's routing table for the specific summarized prefix. Finally, test end-to-end connectivity using ping or traceroute to ensure the summary works.

189
MCQeasy

What is the default OSPF dead interval on an Ethernet broadcast network?

A.10 seconds
B.30 seconds
C.40 seconds
D.120 seconds
AnswerC

OSPF derives the dead interval as four times the hello interval. On an Ethernet broadcast network the default hello is 10 seconds, giving a dead interval of 40 seconds, which matches the stem's broadcast media constraint rather than the 120-second non-broadcast default.

Why this answer

On an Ethernet broadcast network, OSPF defaults to a hello interval of 10 seconds and a dead interval of 40 seconds (four times the hello interval). This is defined in RFC 2328 and is the standard for broadcast multiaccess networks like Ethernet. Option C is correct because the dead interval is explicitly 40 seconds in this scenario.

Exam trap

Cisco often tests the distinction between broadcast and NBMA networks, where candidates mistakenly apply the NBMA dead interval (120 seconds) to Ethernet broadcast networks, or confuse the hello interval (10 seconds) with the dead interval.

How to eliminate wrong answers

Option A is wrong because 10 seconds is the default OSPF hello interval on broadcast networks, not the dead interval. Option B is wrong because 30 seconds is not a standard OSPF timer value; it might be confused with the dead interval on non-broadcast networks (which is 120 seconds) or a misremembered multiplier. Option D is wrong because 120 seconds is the default dead interval on NBMA (Non-Broadcast Multi-Access) networks, such as Frame Relay, where the hello interval is 30 seconds, not on Ethernet broadcast networks.

190
MCQmedium

A network engineer runs the following command to troubleshoot route redistribution: R1# debug ip routing IP: route table insert (10.10.10.0/24 via 192.168.1.1, ospf 1) metric [110/20] IP: route table insert (10.10.10.0/24 via 10.1.1.2, eigrp 100) metric [90/158720] IP: route table delete (10.10.10.0/24 via 192.168.1.1, ospf 1) metric [110/20] IP: route table insert (10.10.10.0/24 via 10.1.1.2, eigrp 100) metric [90/158720] What does this output indicate?

A.The router is load-balancing between OSPF and EIGRP routes.
B.The EIGRP route replaces the OSPF route due to lower administrative distance.
C.The OSPF route is preferred due to lower metric.
D.Both routes are installed in the routing table.
AnswerB

EIGRP's administrative distance of 90 beats OSPF's 110, so the EIGRP path is installed and the OSPF entry removed from the routing table. The debug shows the OSPF route deleted immediately after the EIGRP insert, confirming the lower-AD route wins.

Why this answer

The debug output shows the OSPF route (AD 110) being inserted first, then the EIGRP route (AD 90) being inserted, followed by the deletion of the OSPF route and re-insertion of the EIGRP route. This sequence indicates that the EIGRP route replaces the OSPF route because EIGRP has a lower administrative distance (90 vs. 110), making it more trustworthy. The routing table only keeps the best route based on AD, not metric, when comparing routes from different protocols.

Exam trap

Cisco often tests the distinction between administrative distance and metric, trapping candidates who assume that a lower metric (like OSPF's 20) automatically makes a route preferred, when in fact AD is the first criterion for routes from different protocols.

How to eliminate wrong answers

Option A is wrong because load-balancing requires multiple routes with equal administrative distance and equal metric to the same destination, but here the routes have different ADs (110 vs. 90) and different metrics, so only one route is installed. Option C is wrong because administrative distance, not metric, is the primary tiebreaker when comparing routes from different routing protocols; OSPF's metric [110/20] is irrelevant against EIGRP's lower AD. Option D is wrong because the debug explicitly shows a route table delete for the OSPF route after the EIGRP route is inserted, proving only one route (the EIGRP route) remains in the routing table.

191
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip dhcp database URL : flash:/dhcpdb Read/write : Read/Write Last updated : Mar 01 2020 00:00:00 Status : Last read succeeded. Next write scheduled in 0 seconds. Based on this output, which statement is correct?

A.The DHCP database is stored in NVRAM and is read-only.
B.The DHCP database is stored in flash and is functioning correctly.
C.The DHCP database write failed and needs to be rescheduled.
D.The DHCP database is empty because no bindings exist.
AnswerB

The URL field shows flash:/dhcpdb, confirming the database resides in flash memory, and the status line reports the last read succeeded with the next write scheduled, indicating normal operation. Both the storage location and healthy state match the statement.

Why this answer

The output shows the DHCP database is stored in flash (URL: flash:/dhcpdb) with read/write access, and the status indicates the last read succeeded with a write scheduled in 0 seconds. This confirms the database is functioning correctly, as the router can read and write DHCP bindings to flash memory, which is the default storage location for DHCP database persistence.

Exam trap

Cisco often tests the distinction between DHCP database storage locations (flash vs. NVRAM vs. TFTP) and the interpretation of status messages like 'Last read succeeded' versus 'Last write failed', tricking candidates into assuming a failure or empty database without reading the full output.

How to eliminate wrong answers

Option A is wrong because the URL shows flash:/dhcpdb, not NVRAM, and the access is read/write, not read-only. Option C is wrong because the status clearly states 'Last read succeeded' and 'Next write scheduled in 0 seconds', indicating no failure occurred. Option D is wrong because the output does not provide any information about the number of bindings; the database could contain bindings or be empty, but the status does not indicate emptiness.

192
MCQmedium

A network engineer runs the following command to verify MPLS LDP discovery sources: R1# show mpls ldp discovery detail Output: Local LDP Identifier: 10.0.0.1:0 Discovery Sources: Interfaces: GigabitEthernet0/0 (hello interval 5 s, targeted hello interval 10 s) LDP Id: 10.0.0.2:0, transport address: 10.0.0.2 Hold time: 15 s (local: 15, peer: 15) GigabitEthernet0/1 (hello interval 5 s, targeted hello interval 10 s) LDP Id: 10.0.0.3:0, transport address: 10.0.0.3 Hold time: 15 s (local: 15, peer: 15) What does this output indicate?

A.R1 has discovered two LDP neighbors via link hellos on two different interfaces
B.R1 is using targeted hellos only
C.R1 has no LDP neighbors
D.The LDP session with 10.0.0.2 is down
AnswerA

The output lists two discovery sources under "Interfaces", each showing a peer LDP Identifier and transport address, which confirms neighbours found through link (basic) hellos rather than targeted hellos. Both GigabitEthernet0/0 and GigabitEthernet0/1 satisfy the stem's requirement of verifying LDP discovery sources across two interfaces.

Why this answer

The output shows two discovery sources on GigabitEthernet0/0 and GigabitEthernet0/1, each with a distinct LDP ID (10.0.0.2:0 and 10.0.0.3:0) and transport address, confirming R1 has discovered two LDP neighbors via link (basic) hellos on two different interfaces. The presence of 'Interfaces:' with per-interface LDP IDs and hold times confirms active neighbor discovery, not targeted-only or down sessions.

Exam trap

The trap is confusing link hellos with targeted hellos — candidates may see 'targeted hello interval' in the output and incorrectly conclude targeted hellos are in use, when the neighbors are actually discovered via interface (link) hellos.

How to eliminate wrong answers

Option B is wrong because the output lists discovery under 'Interfaces:' (link hellos), not under a 'Targeted Hellos:' section — targeted hellos would appear separately and are used for non-directly-connected LDP peers. Option C is wrong because two LDP neighbors are clearly listed with their LDP IDs and transport addresses. Option D is wrong because the session with 10.0.0.2 shows a valid LDP ID, transport address, and matching hold times (local: 15, peer: 15), indicating the session is up, not down.

193
MCQmedium

A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco IOS routers. Phase 1 is up, but Phase 2 fails to establish. The engineer suspects a mismatch in the IPsec proposal. Which command would show the configured IPsec transform set and the algorithms being used?

A.show crypto map
B.show crypto isakmp sa
C.show crypto ipsec sa
D.show crypto ipsec transform-set
AnswerD

The show crypto ipsec transform-set command lists all configured IPsec transform sets, including the name and the specific protocols and algorithms (e.g., esp-aes, esp-sha-hmac). This allows the engineer to compare the transform set on both routers and identify any mismatch in encryption or authentication algorithms that would cause Phase 2 negotiation to fail. It is the most direct way to verify the configured IPsec proposal.

Why this answer

When Phase 2 fails, the most likely cause is a mismatch in the IPsec transform set. The show crypto ipsec transform-set command reveals the configured algorithms for each transform set, enabling comparison between peers. While other commands show SA status or map references, only this command directly displays the transform set details needed to identify the mismatch.

Exam trap

The trap here is assuming that show crypto ipsec sa will show the configured transform set; it only shows established SAs, which may be absent when Phase 2 fails.

194
MCQmedium

Consider the following partial configuration on router R6: flow exporter EXPORTER-3 destination 192.168.2.200 source Loopback0 transport udp 2055 template data timeout 120 ! flow monitor MONITOR-6 exporter EXPORTER-3 record netflow ipv4 original-input ! interface GigabitEthernet0/6 ip flow monitor MONITOR-6 input ! What is the effect of the 'template data timeout 120' command?

A.The router will resend the NetFlow v9 template to the collector every 120 seconds to ensure the collector has the latest template.
B.The router will wait 120 seconds before sending any flow data after the first template is sent.
C.The router will export flow data only if the template has been successfully acknowledged by the collector within 120 seconds.
D.The router will store flow data for 120 seconds before exporting to allow batching.
AnswerA

The template data timeout sets the resend interval for NetFlow v9 template records on the exporter. Every 120 seconds the router retransmits the template to 192.168.2.200:2055, ensuring the collector can decode subsequent flow records even after a restart.

Why this answer

The 'template data timeout 120' command under the flow exporter configuration sets the refresh interval for NetFlow v9 (or IPFIX) templates to 120 seconds. Because NetFlow v9/IPFIX templates are sent periodically (not on every packet), the exporter re-transmits the template to the collector every 120 seconds so the collector can continue to decode flow records even if it missed the initial template or restarted. This ensures template freshness and collector synchronization.

Exam trap

The trap here is confusing the template refresh timer with flow cache/active timeouts or with a reliability/ACK mechanism — candidates often assume UDP NetFlow has acknowledgments or that the timer delays data export.

How to eliminate wrong answers

Option B is wrong because the timeout does not delay flow data transmission; flow records are exported as soon as flows expire or the active timeout is reached, independent of the template refresh timer. Option C is wrong because NetFlow v9/IPFIX over UDP is unacknowledged — there is no collector ACK mechanism, so the exporter cannot condition export on template acknowledgment. Option D is wrong because flow data batching is governed by active/inactive timeouts (e.g., 'cache timeout active'), not by the template data timeout, which only controls template refresh.

195
Multi-Selectmedium

Which TWO commands would a network engineer use to verify the BGP next-hop reachability issue when a route is not being installed in the routing table? (Choose TWO.)

Select 2 answers
A.show ip bgp
B.show ip route
C.show ip bgp neighbors
D.show ip bgp summary
E.debug ip bgp updates
AnswersA, B

Displays the BGP table; routes with unreachable next hops may show as 'r' or not be installed.

Why this answer

Option A, `show ip bgp`, is correct because it displays the BGP table including each prefix's next-hop address and the route's status codes, so the engineer can see whether the next hop is marked inaccessible (e.g., a leading `r` or missing `*>`), which directly reveals the next-hop reachability problem preventing installation. Option B, `show ip route`, is correct because it verifies whether the BGP next-hop address is actually present in the IP routing table (via a connected, static, or IGP route); if the next hop is not resolvable in the RIB, BGP will not install the route, so this command confirms the reachability failure. Option C, `show ip bgp neighbors`, is not the best choice because it shows neighbor session details and capabilities rather than the per-prefix next-hop reachability status.

Option D, `show ip bgp summary`, only gives neighbor state and prefix counts, not next-hop resolution. Option E, `debug ip bgp updates`, would show update messages but is intrusive and does not directly verify next-hop reachability in the routing table.

Exam trap

300-410 often tests the distinction between commands that show BGP neighbor status versus those that reveal next-hop reachability, causing candidates to mistakenly select 'show ip bgp neighbors' or 'show ip bgp summary' instead of the correct 'show ip bgp' and 'show ip route'.

196
MCQmedium

In MPLS LDP, what is the default label retention mode on Cisco IOS-XE routers?

A.Liberal Label Retention mode
B.Conservative Label Retention mode
C.Ordered Label Retention mode
D.Independent Label Retention mode
AnswerA

Cisco IOS-XE defaults to Liberal Label Retention, keeping all received label bindings regardless of whether the next hop is currently used. This differs from Conservative mode, which discards labels not associated with the feasible next hop.

Why this answer

The default label retention mode is Liberal, meaning that a router retains all label bindings received from neighbors, even if the neighbor is not the next hop for the FEC.

197
MCQhard

Two routers are configured with EIGRP and have a neighbor relationship. One router has a route to 192.168.1.0/24 with metric 100. The other router has a route to the same prefix with metric 200. An engineer configures an offset-list on the first router to increase the metric of 192.168.1.0/24 by 50, expecting the second router to prefer its own route. Unexpectedly, the second router still prefers the first router's route after the offset. Which is the most likely explanation?

A.The offset-list increased the metric from 100 to 150, which is still lower than the second router's metric of 200, so the second router still prefers the first router's route.
B.The offset-list must be applied inbound on the second router to increase the metric of the received route.
C.The offset-list command only affects feasible distance, not advertised distance, so the second router ignores it.
D.The second router has a higher administrative distance for the route, so it always prefers the first router's route.
AnswerA

Offset-lists add the configured value to the metric before advertisement. Raising 100 to 150 still beats the second router's local metric of 200, so its own route remains less preferred and the first router's route is still selected.

Why this answer

The offset-list adds 50 to the metric of the matched route on the first router, changing its advertised metric from 100 to 150. Since 150 is still lower than the second router's local metric of 200, the second router continues to prefer the route learned from the first router. The offset was insufficient to make the second router's own route preferable.

Exam trap

300-410 often tests metric arithmetic with offset-lists — candidates assume any offset changes path preference without checking whether the new metric actually exceeds the competing route's metric.

How to eliminate wrong answers

Option B is wrong because an offset-list can be applied inbound or outbound; applying it outbound on the first router correctly increases the advertised metric, and applying it inbound on the second router would also work, but the question's scenario already applied it and the math explains the outcome. Option C is wrong because offset-lists affect both the advertised distance and the feasible distance — they modify the metric used in EIGRP computations. Option D is wrong because administrative distance is not the tiebreaker here; both routes are EIGRP internal routes with the same AD, so the metric determines preference.

198
MCQmedium

Consider the following partial configuration on router R4: flow exporter EXPORTER-2 destination 10.10.10.1 source Loopback0 transport udp 9996 option interface-table option sampler-table ! flow monitor MONITOR-4 exporter EXPORTER-2 record netflow ipv4 original-input ! interface GigabitEthernet0/4 ip flow monitor MONITOR-4 input ! What is the purpose of the 'option interface-table' and 'option sampler-table' commands under the exporter?

A.They instruct the router to periodically export metadata about interfaces and samplers to the collector, aiding in data interpretation.
B.They enable the router to sample traffic based on interface and sampler tables before exporting.
C.They limit the export to only interface and sampler statistics, ignoring flow records.
D.They are required for the exporter to function; without them, no data is exported.
AnswerA

These options make the exporter send periodic metadata records describing interface names and sampler configuration to the collector. Without them, the collector receives flow records referencing interface or sampler IDs it cannot resolve, hindering interpretation.

Why this answer

The 'option interface-table' and 'option sampler-table' commands under a flow exporter enable the periodic export of metadata about interfaces and samplers to the NetFlow collector. This metadata is sent as separate option template records, allowing the collector to correctly interpret flow records that reference interface indices or sampler IDs. Without these options, the collector would receive flow data but lack the mapping to resolve interface names or sampling parameters, reducing the usefulness of the exported flows.

Exam trap

The trap here is confusing the export of metadata with the configuration of sampling itself; candidates often think 'option sampler-table' enables sampling, but it only exports sampler information.

How to eliminate wrong answers

Option B is wrong because these commands do not enable sampling; sampling is configured separately (e.g., with 'sampler' and 'ip flow monitor ... sampler' commands). They only export metadata about samplers, not activate sampling. Option C is wrong because the commands do not limit the export to only interface and sampler statistics; flow records are still exported according to the flow monitor configuration.

Option D is wrong because the exporter functions without these commands; they are optional and only enhance the collector's ability to interpret data. Flow export occurs regardless of whether these options are configured.

199
MCQeasy

What is the default OSPF hello interval on a Cisco IOS-XE router for a broadcast network type?

A.10 seconds
B.30 seconds
C.40 seconds
D.60 seconds
AnswerA

On a Cisco IOS-XE router, the default OSPF hello interval for a broadcast network type is 10 seconds, with a corresponding dead interval of 40 seconds. This matches the timer values shown for broadcast interfaces unless manually overridden.

Why this answer

On Cisco IOS-XE routers, the default OSPF hello interval for broadcast and point-to-point network types is 10 seconds, with a corresponding dead interval of 40 seconds (4× the hello). This matches the OSPF standard for these multi-access and point-to-point media, where faster hello timers are used to detect neighbor loss quickly. Non-broadcast (NBMA) and point-to-multipoint networks use a 30-second hello by default instead.

Exam trap

The trap here is confusing the hello interval with the dead interval — 40 seconds is the dead interval on broadcast networks, so candidates who mix up the two timers pick option C.

How to eliminate wrong answers

Option B is wrong because 30 seconds is the default hello interval for NBMA and point-to-multipoint OSPF network types, not broadcast. Option C is wrong because 40 seconds is the default OSPF dead interval on broadcast networks, not the hello interval — candidates often confuse the two timers. Option D is wrong because 60 seconds is not a default OSPF hello value on any standard Cisco network type; it may be confused with other protocol timers such as EIGRP or HSRP.

200
MCQhard

A network engineer is troubleshooting NAT for a VoIP phone that uses SIP. The phone is at 192.168.2.10, and the router performs PAT to the outside interface 198.51.100.1. The phone can register with the SIP server, but calls fail after 30 seconds. The engineer notices that the SIP signaling includes the phone's private IP in the SDP body. What is the most likely cause?

A.The PAT port range is exhausted.
B.The router's SIP ALG is disabled, so the private IP in the SDP is not translated.
C.The phone's default gateway is misconfigured.
D.The outside interface has a firewall blocking UDP ports.
AnswerB

SIP embeds the phone's private address inside the SDP body of the signalling payload. PAT rewrites only packet headers, not payload contents, so without the SIP ALG inspecting and translating that embedded address, the remote party cannot return media.

Why this answer

The SIP signaling includes the phone's private IP in the SDP body, which is used for media negotiation. When the router's SIP Application Layer Gateway (ALG) is disabled, it does not inspect and translate the private IP addresses embedded in the SDP payload. As a result, the SIP server sends media (RTP) to the private IP 192.168.2.10, which is unreachable from outside, causing the call to fail after the initial registration and signaling succeed.

Exam trap

Cisco often tests the distinction between control plane (SIP signaling) and data plane (RTP media) failures, and the trap here is that candidates assume registration success means NAT is working correctly, overlooking the need for ALG to translate embedded IPs in the SDP body.

How to eliminate wrong answers

Option A is wrong because PAT port exhaustion would cause all new outbound translations to fail, not specifically cause calls to fail after 30 seconds while registration succeeds. Option C is wrong because a misconfigured default gateway would prevent the phone from reaching the SIP server at all, not allow registration and then fail calls after 30 seconds. Option D is wrong because a firewall blocking UDP ports would likely prevent registration or call setup entirely, not allow the call to proceed for 30 seconds before failing.

201
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub router. The hub must dynamically discover spoke-to-spoke tunnels while still using the hub for initial registration. Which technology allows the hub to redirect spoke traffic directly to another spoke?

A.NHRP shortcut
B.NHRP redirect
C.NHRP registration
D.NHRP resolution
AnswerB

NHRP redirect is a Phase 3 DMVPN feature where the hub sends an NHRP redirect message to the source spoke when it detects traffic that could be sent directly to another spoke. This enables the spoke to initiate an NHRP resolution for the destination spoke's NBMA address and build a direct tunnel, optimizing the path.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to inform a source spoke that a more optimal direct path exists to the destination spoke. The hub inspects incoming packets and, upon determining that the destination is reachable via another spoke, sends an NHRP redirect message. The source spoke then initiates NHRP resolution for the destination and establishes a direct spoke-to-spoke tunnel, achieving Phase 3 shortcuts.

Exam trap

The trap here is confusing NHRP redirect with NHRP shortcut; redirect is the hub's action to signal a better path, while shortcut is the spoke's action to use it.

202
Drag & Dropmedium

Drag and drop the steps to verify and validate the EIGRP operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Begin by checking the overall EIGRP process status, then verify the neighbor table for adjacency, examine the topology table for feasible successors, review the routing table for installed routes, and finally use debug commands to validate ongoing operations if needed.

203
MCQmedium

A network engineer is configuring a VRF-aware IPsec VPN. The engineer needs to ensure that the IPsec tunnel traffic is forwarded within the correct VRF on the router. Which command must be configured under the crypto map to bind the IPsec tunnel to a specific VRF?

A.set vrf VPN-CORP
B.set ip vrf VPN-CORP
C.ip vrf forwarding VPN-CORP
D.vrf forwarding VPN-CORP
AnswerA

The set vrf command under a crypto map entry specifies the VRF that the IPsec tunnel will use for forwarding. It ensures that the encrypted traffic is routed within the correct VRF, enabling VRF-aware IPsec. This is the correct command to bind the tunnel to a VRF.

Why this answer

To bind an IPsec tunnel to a VRF in a VRF-aware IPsec configuration, the set vrf command is used under the crypto map entry. This ensures that the tunnel's traffic is forwarded using the specified VRF's routing table, allowing overlapping address spaces and segmentation.

Exam trap

The trap here is confusing interface-level VRF commands like vrf forwarding with crypto map-level commands, leading to selecting the wrong syntax.

204
MCQhard

A network engineer is troubleshooting a DHCP relay configuration on a Cisco IOS router. The router is configured with the ip helper-address 10.1.1.1 command on interface GigabitEthernet0/0, but clients on the 192.168.1.0/24 subnet are not receiving IP addresses from the DHCP server at 10.1.1.1. The engineer verifies that the DHCP server is operational and has a pool for 192.168.1.0/24. What is the most likely cause?

A.The DHCP relay agent is not enabled globally with the service dhcp command.
B.The DHCP server does not have a route back to the 192.168.1.0/24 subnet.
C.The ip helper-address command must be configured with the subnet mask of the DHCP server.
D.The ip helper-address command is configured on the wrong interface.
AnswerB

For DHCP relay to work, the DHCP server must have a route back to the client subnet to send the DHCPOFFER. If the server lacks a route to 192.168.1.0/24, it cannot deliver the offer, and clients will not receive addresses. This is a common oversight when the server is on a different subnet and no default gateway or static route is configured.

Why this answer

The most likely cause is that the DHCP server does not have a route back to the 192.168.1.0/24 subnet. Without a return route, the server cannot send DHCPOFFER messages to the relay agent, so clients never receive an address. The other options are either incorrect syntax or not applicable because the relay agent is typically enabled by default and the helper address is on the correct interface.

Exam trap

The trap here is assuming that the DHCP relay configuration is at fault when the issue is actually on the DHCP server side, specifically the lack of a return route to the client subnet.

205
MCQhard

A network engineer is troubleshooting an OSPFv2 adjacency issue between two routers across a Frame Relay network. R1 and R2 are connected via a point-to-point subinterface. The engineer configures 'ip ospf network point-to-point' on both subinterfaces. However, the adjacency does not form. 'show ip ospf interface' on R1 shows the interface is up and OSPF is enabled, but no neighbors are seen. What is the most likely cause?

A.The OSPF network type is set to broadcast, causing a DR/BDR election that fails on a point-to-point subinterface.
B.The subinterface is not configured with an IP address.
C.The Frame Relay map is missing or the DLCI is not assigned to the subinterface.
D.The OSPF hello and dead timers are mismatched between R1 and R2.
AnswerC

OSPF point-to-point mode still relies on Frame Relay Layer 2 reachability. Without a frame-relay map or DLCI assigned to the subinterface, hellos cannot traverse the PVC, so the adjacency never forms despite OSPF being enabled.

Why this answer

The most likely cause is that the Frame Relay map is missing or the DLCI is not assigned to the point-to-point subinterface. Even though OSPF is enabled and the interface is up, OSPF hellos are multicast to 224.0.0.5; without a Frame Relay map or a DLCI assignment, those multicast packets cannot be sent across the Frame Relay cloud. Therefore, no OSPF neighbor relationship can form.

The other options are either already addressed in the scenario or less likely given the symptoms.

Exam trap

The trap here is assuming that because the interface is 'up' and OSPF is enabled, Layer 3 connectivity is functional; candidates often overlook that Frame Relay requires explicit mapping or DLCI assignment for multicast traffic like OSPF hellos to traverse the cloud.

How to eliminate wrong answers

Option A is wrong because the engineer explicitly configured 'ip ospf network point-to-point', which disables DR/BDR election; the network type is not broadcast. Option B is wrong because 'show ip ospf interface' would not show the interface as up and OSPF-enabled if it lacked an IP address; OSPF requires an IP address to operate. Option D is wrong because hello/dead timer mismatches typically occur when network types differ, but here both sides are configured as point-to-point, so timers should match by default; moreover, a timer mismatch would still allow hellos to be sent, but they would be ignored, which is not the primary issue when no neighbors are seen at all.

206
MCQmedium

A network engineer runs the following command to troubleshoot a Device Access Control issue: R1# show mpls ldp bindings 10.10.10.0 24 lib entry: 10.10.10.0/24, rev 2 local binding: label: 101 remote binding: lsr: 10.1.1.2:0, label: 102 remote binding: lsr: 10.1.2.2:0, label: 103 What does this output indicate?

A.The router has a local label of 101 for the prefix and has learned two remote labels from two different neighbors.
B.The router has only a local label of 101; the remote bindings are not used because they are from the same LSR.
C.The label 102 is the local label for the prefix 10.10.10.0/24.
D.The router has no label for the prefix because the lib entry is incomplete.
AnswerA

The output shows a local binding of label 101 for 10.10.10.0/24, plus two remote bindings from LSRs 10.1.1.2:0 and 10.1.2.2:0 with labels 102 and 103. This confirms the router has assigned its own label and received label mappings from two LDP neighbours, satisfying the troubleshooting requirement.

Why this answer

The output of 'show mpls ldp bindings 10.10.10.0 24' displays the Label Information Base (LIB) entry for prefix 10.10.10.0/24. The 'local binding: label: 101' indicates that this router has assigned label 101 to the prefix. The two 'remote binding' lines show that two different LDP neighbors (LSR IDs 10.1.1.2 and 10.1.2.2) have advertised labels 102 and 103 respectively for the same prefix.

This is the normal operation of LDP, where a router learns multiple remote labels for the same FEC from different peers.

Exam trap

Cisco often tests the distinction between local and remote bindings in the LIB, and the trap here is that candidates may confuse the 'local binding' with a remote label or assume that multiple remote bindings from different LSRs are not used, when in fact they are all valid entries for potential forwarding paths.

How to eliminate wrong answers

Option B is wrong because the remote bindings are indeed used; they are from two different LSRs (10.1.1.2 and 10.1.2.2), not the same LSR, and each provides a viable label-switched path. Option C is wrong because label 102 is a remote binding learned from LSR 10.1.1.2, not a local binding; the local label is 101. Option D is wrong because the LIB entry is complete, showing both a local binding and two remote bindings, which is a fully populated entry for the prefix.

207
MCQmedium

A network administrator is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers that uses IKEv2. Phase 1 is up, but Phase 2 fails. The administrator reviews the configuration and notices that the transform set on one router includes esp-aes 256 esp-sha256-hmac, while the other router has esp-aes 256 esp-sha512-hmac. The administrator wants to ensure the Phase 2 SA is established. Which action should the administrator take?

A.Configure a matching transform set on both routers with the same encryption and integrity algorithms.
B.Change the IKEv2 proposal to use a different DH group.
C.Restart the IKEv2 process on both routers to clear the Phase 1 SA and force renegotiation.
D.Enable perfect forward secrecy on both routers by configuring the same DH group in the IPsec profile.
AnswerA

Phase 2 (IPsec SA) requires both peers to agree on the transform set, which specifies the encryption and integrity algorithms. The mismatch between esp-sha256-hmac and esp-sha512-hmac prevents the IPsec SA from being established. Configuring identical transform sets on both routers, such as esp-aes 256 esp-sha256-hmac, ensures both peers propose and accept the same algorithms, allowing Phase 2 to complete successfully.

Why this answer

IPsec Phase 2 requires both peers to agree on a transform set that defines the encryption and integrity algorithms. The mismatch between esp-sha256-hmac and esp-sha512-hmac means the peers cannot agree on the integrity algorithm, so the IPsec SA fails to establish. The administrator must configure a matching transform set on both routers, ensuring the encryption and integrity algorithms are identical, to allow Phase 2 to complete.

Exam trap

The trap here is assuming that Phase 2 failures are caused by Phase 1 parameters like DH group or IKEv2 proposal settings, rather than the transform set mismatch.

208
MCQeasy

Which BFD session state indicates that the session is fully established and operational?

A.Down
B.Init
C.Up
D.AdminDown
AnswerC

Up is the operational state reached after both systems complete the three-way handshake and agree on timers and discriminators. Down, Init and AdminDown precede or preclude full establishment, so Up alone confirms the session is established and actively monitoring the path.

Why this answer

The BFD session state 'Up' indicates that the session is fully established and operational. In BFD, the Up state means both routers have agreed on session parameters and are exchanging control packets successfully, allowing rapid failure detection.

Exam trap

300-410 often tests the BFD state machine, and candidates may confuse Init with Up; Init is a transitional state, while Up is fully operational.

How to eliminate wrong answers

Option A is wrong because Down means the session is not operational. Option B is wrong because Init indicates the session is in the process of being established but not yet fully up. Option D is wrong because AdminDown indicates the session was administratively disabled.

209
MCQhard

An EIGRP network is experiencing stuck-in-active (SIA) routes after a link failure. Router R1 has the following relevant configuration: router eigrp 100 network 10.0.0.0 0.255.255.255 Router R2 shows: show ip eigrp topology 10.1.1.0/24 IP-EIGRP topology entry for 10.1.1.0/24 State: Active, 00:01:30, Reply status 10.2.2.2, 10.3.3.3 What is the root cause?

A.Query scope is too wide; configure stub routing or summarization to limit queries.
B.The K-values are mismatched; check metric weights.
C.The network command includes too many interfaces; use passive-interface.
D.The hold time is too short; increase to 180 seconds.
AnswerA

The wide network statement causes R1 to flood queries for the lost route to every EIGRP neighbour, and replies from distant routers exceed the active timer, producing stuck-in-active state. Stub routing or summarisation confines the query domain, so only relevant routers respond.

Why this answer

Stuck-in-Active (SIA) occurs when a router sends a query for a lost route and does not receive a reply from all neighbors within the active timer (default 3 minutes). The output shows the route in Active state with replies pending from 10.2.2.2 and 10.3.3.3, indicating the query propagated widely. The root cause is that the query scope is too broad — the 'network 10.0.0.0 0.255.255.255' command on R1 activates EIGRP on all interfaces in that range, so queries flood the entire domain.

Limiting query scope with EIGRP stub routing on spoke routers or route summarization prevents this.

Exam trap

The trap is assuming SIA is caused by a timer or metric mismatch; in reality, SIA is a query-scope problem, and the fix is stub routing or summarization, not tuning hold timers or K-values.

How to eliminate wrong answers

Option B is wrong because mismatched K-values prevent adjacency formation entirely (neighbors never come up), rather than causing a route to remain stuck in Active after a link failure. Option C is wrong because using passive-interface would suppress adjacencies on those interfaces, but the problem is query propagation, not the number of interfaces running EIGRP — passive-interface alone does not solve SIA caused by wide query scope. Option D is wrong because EIGRP hold time (default 15s, not 180s) affects neighbor liveness detection, not query/reply behavior; increasing it would not resolve SIA and 180s is not an EIGRP hold-time default.

210
MCQmedium

A network engineer is troubleshooting a DMVPN Phase 3 hub-and-spoke topology. Spoke routers are Cisco IOS devices running EIGRP as the routing protocol. The engineer wants to ensure that spoke-to-spoke traffic does not go through the hub after the initial path setup, and that spoke routers can dynamically form direct tunnels. Which NHRP command must be configured on the hub to enable this behavior?

A.ip nhrp map multicast dynamic
B.ip nhrp redirect
C.ip nhrp network-id 1
D.ip nhrp shortcut
AnswerB

The 'ip nhrp redirect' command on the hub enables NHRP redirect messages, which inform spokes of a better direct path to another spoke. This allows spoke-to-spoke communication without traversing the hub after initial resolution. It is essential for DMVPN Phase 3 and works with 'ip nhrp shortcut' on spokes.

Why this answer

For DMVPN Phase 3, the hub must be configured with 'ip nhrp redirect' to send redirect messages to spokes, allowing them to establish direct tunnels. Spokes must have 'ip nhrp shortcut' to act on those redirects. Without the hub redirect, spokes would continue sending traffic through the hub even after initial NHRP resolution.

Exam trap

The trap here is confusing the roles of 'ip nhrp redirect' and 'ip nhrp shortcut', mistakenly placing the shortcut command on the hub instead of the spoke.

211
MCQhard

A network engineer configures mutual redistribution between EIGRP and OSPF on a DMVPN hub router. The EIGRP domain includes the DMVPN tunnel network, and OSPF includes a corporate backbone. Unexpectedly, after a few minutes, the routing table on the hub shows oscillating routes between EIGRP and OSPF for the same prefix, causing intermittent connectivity. Which is the most likely explanation?

A.The mutual redistribution creates a routing loop because the redistributed routes are re-injected into the original protocol without proper filtering, causing the hub to prefer the redistributed route with a lower AD.
B.The DMVPN tunnel interface is not included in the OSPF process, causing the redistributed routes to have an incorrect next-hop that points to the tunnel interface.
C.The EIGRP and OSPF processes are using different metric styles, causing the redistributed routes to have infinite metrics and be ignored.
D.The hub router's routing table is overloaded due to the DMVPN tunnel being a multipoint interface, causing route flapping.
AnswerA

Without route tagging, a route redistributed from EIGRP into OSPF (AD 110) and then back into EIGRP (AD 170) may be preferred over the original EIGRP internal route (AD 90) if the AD is misconfigured, but typically the original internal route has lower AD. However, if the route is external in EIGRP, the AD is 170, so the OSPF route (110) is preferred, causing a loop.

Why this answer

Mutual redistribution between EIGRP and OSPF without proper filtering or tag-based loop prevention causes routes to be redistributed back into their original protocol. The hub may then prefer the redistributed route due to a lower administrative distance, creating a feedback loop that manifests as oscillating routes and intermittent connectivity.

Exam trap

300-410 often tests redistribution loop scenarios; candidates may blame interface configuration or metrics instead of recognizing the classic feedback loop caused by mutual redistribution without filtering.

How to eliminate wrong answers

Option B is wrong because an incorrect next-hop would cause reachability failures, not oscillating routes between protocols; the tunnel interface inclusion is a separate design concern. Option C is wrong because metric style differences are handled by seed metrics during redistribution; they do not cause infinite metrics unless misconfigured, and the symptom would be missing routes, not flapping. Option D is wrong because a multipoint tunnel interface does not inherently cause route flapping; the issue is redistribution feedback, not interface type.

212
MCQhard

An engineer configures a site-to-site IPsec VPN between two routers using OSPF as the routing protocol. The OSPF neighbor becomes stuck in EXSTART state. The engineer verifies that the IPsec tunnel is up and that both routers can ping each other's tunnel interfaces. What is the most likely cause of the OSPF adjacency issue?

A.The OSPF network type on the tunnel interface is set to non-broadcast, preventing DBD exchange.
B.The IPsec transform set uses ESP with authentication, adding 22 bytes of overhead, reducing the tunnel MTU to 1478 bytes, causing OSPF DBD packets larger than 1478 bytes to be dropped.
C.The OSPF hello and dead intervals are mismatched between the two routers.
D.The IPsec tunnel is using transport mode instead of tunnel mode, corrupting OSPF packets.
AnswerB

IPsec encapsulation adds overhead (e.g., 22 bytes for ESP-AES + SHA), reducing the effective MTU. OSPF DBD packets default to 1500 bytes on Ethernet, but if the tunnel MTU is lower, they are fragmented or dropped, leading to EXSTART state.

Why this answer

When OSPF neighbors are stuck in EXSTART state, it indicates a problem with Database Description (DBD) packet exchange. With an IPsec tunnel MTU of 1478 bytes (1500 minus 22 bytes for ESP authentication overhead), OSPF DBD packets that exceed this size are fragmented or dropped. Since IPsec does not support fragmentation of encrypted packets, the DBD exchange fails, preventing OSPF from progressing past EXSTART.

Exam trap

Cisco often tests the distinction between OSPF states—candidates confuse EXSTART (DBD exchange failure) with other states like INIT (hello mismatch) or 2-WAY (neighbor discovery), and overlook the impact of IPsec overhead on MTU and packet fragmentation.

How to eliminate wrong answers

Option A is wrong because the non-broadcast network type does not prevent DBD exchange; it only requires manual neighbor configuration and uses unicast for OSPF packets, but DBD exchange can still occur. Option C is wrong because mismatched hello/dead intervals cause OSPF to get stuck in INIT or 2-WAY state, not EXSTART; EXSTART is specifically about DBD negotiation. Option D is wrong because transport mode is used for host-to-host VPNs and does not inherently corrupt OSPF packets; tunnel mode is typical for site-to-site VPNs, but mode choice does not cause EXSTART issues.

213
MCQmedium

A network engineer is configuring a Cisco router to authenticate OSPF neighbors using MD5. The router is connected to two OSPF neighbors on the same subnet. The engineer wants to enable MD5 authentication on the interface with a key ID of 1 and a password of 'Cisco123'. Which command sequence correctly accomplishes this?

A.router ospf 1 area 0 authentication ip ospf message-digest-key 1 md5 Cisco123
B.router ospf 1 area 0 authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
C.interface GigabitEthernet0/0 ip ospf authentication-key Cisco123 ip ospf authentication message-digest
D.interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
AnswerD

This sequence enables OSPF MD5 authentication on the interface and configures the key ID and password. The 'ip ospf authentication message-digest' command activates MD5 authentication for OSPF on that interface, and 'ip ospf message-digest-key 1 md5 Cisco123' defines the key. This is the correct method to enable MD5 authentication per interface. Both commands are required; without the first, the key is configured but authentication is not enabled.

Why this answer

To enable OSPF MD5 authentication on a specific interface, you must enter interface configuration mode and issue both 'ip ospf authentication message-digest' to turn on MD5 authentication and 'ip ospf message-digest-key 1 md5 Cisco123' to define the key. This method allows per-interface authentication, which is suitable when only certain interfaces require MD5. The other options either misplace the key command, use plaintext authentication, or configure area-wide authentication incorrectly.

Exam trap

The trap here is confusing interface-level MD5 authentication commands with area-level authentication commands, and misplacing the key configuration under router ospf mode instead of interface mode.

214
MCQmedium

A network engineer is configuring MPLS Layer 3 VPN on a Cisco IOS XE router. The engineer needs to enable the provider edge (PE) router to exchange VPNv4 routes with another PE router. Which address family must be configured under the BGP routing process to achieve this?

A.address-family ipv4 vrf
B.address-family ipv6 unicast
C.address-family ipv4 unicast
D.address-family vpnv4 unicast
AnswerD

This address family is specifically designed to carry VPNv4 routes with MPLS labels between PE routers. It enables the exchange of customer VPN routes along with their associated route targets and MPLS labels. Configuring this address family under BGP is essential for MPLS L3VPN operation.

Why this answer

To exchange VPNv4 routes between PE routers in an MPLS L3VPN environment, the BGP process must be configured with the address-family vpnv4 unicast command. This enables the PE routers to exchange VPNv4 prefixes along with MPLS labels and route targets. The other address families do not support VPNv4 route exchange.

Exam trap

The trap here is confusing the VPNv4 address family with the IPv4 VRF address family, which is used for PE-CE routing.

215
Multi-Selecthard

Which TWO statements about BFD echo mode are true? (Choose TWO.)

Select 2 answers
A.Echo packets are generated by the sending router and forwarded back by the remote router.
B.Echo mode reduces the processing load on the remote router's control plane.
C.Echo mode requires a separate BFD session for each direction.
D.Echo mode increases the number of BFD control packets sent between routers.
E.Echo mode is enabled by default on all interfaces.
AnswersA, B

In echo mode the local router transmits echo packets that the remote router simply reflects back along the same path, without the remote system maintaining its own BFD session state. This differs from asynchronous mode, where both routers independently send control packets to each other.

Why this answer

Option A is correct because in BFD echo mode the local (sending) router originates echo packets with its own address as the destination, and the remote router simply loops them back along the reverse path without processing them as BFD control packets. Option B is correct because the remote router only has to forward the echoed packet at the data plane, so it does not run BFD state-machine processing, which reduces the load on its control plane. Option C is incorrect because echo mode still uses a single BFD session; the echo function is an addition to that session, not a separate per-direction session.

Option D is incorrect because echo mode actually reduces the number of BFD control packets exchanged, since the echo packets replace frequent control-packet transmission. Option E is incorrect because BFD echo mode is not enabled by default on interfaces; it must be explicitly configured.

216
MCQhard

A service provider network uses OSPF with route summarization on Area Border Routers (ABRs). Router R1 (ABR) has the configuration: router ospf 1 area 1 range 10.1.0.0 255.255.240.0 area 1 range 10.1.16.0 255.255.240.0 Router R2 (internal to area 1) shows: R2# show ip route ospf 10.1.0.0/20 is subnetted, 1 subnets O IA 10.1.0.0/20 [110/2] via 10.2.1.1, 00:00:15, Serial0/0/0 10.1.16.0/20 is subnetted, 1 subnets O IA 10.1.16.0/20 [110/2] via 10.2.1.1, 00:00:10, Serial0/0/0 10.1.32.0/20 [110/3] via 10.2.1.2, 00:00:05, Serial0/0/1 R2 is missing a route to 10.1.48.0/20. What is the root cause?

A.The ABR R1 has a missing 'area 1 range 10.1.48.0 255.255.240.0' command.
B.R2 has a routing table limit that prevents installation of the route.
C.R1's OSPF process has a distribute-list blocking the route.
D.The missing route is a result of OSPF route filtering at the area boundary.
AnswerA

The summary range for 10.1.48.0/20 is not configured, so that route is not advertised into area 0.

Why this answer

The ABR R1 configured two summary ranges for area 1, but the missing route 10.1.48.0/20 is not covered by either summary. OSPF summarization on the ABR creates Type 3 LSAs for the configured ranges, but any routes not falling within those ranges are not advertised as summaries and are also not advertised as individual routes (unless the 'no discard-route' option is used). This causes the missing route.

The correct fix is to add an additional summary range covering 10.1.48.0/20 or use a broader summary.

217
MCQeasy

A network engineer runs the following command to troubleshoot a VRF route issue: R1# show ip route vrf CUSTOMER summary IP routing table name is CUSTOMER (0x1) IP routing table maximum-paths is 32 Route Source Networks Subnets Overhead Memory (bytes) connected 2 0 0 320 static 1 0 0 160 eigrp 100 3 0 0 480 Internal 3 Total 6 0 0 960 What does this output indicate?

A.The VRF CUSTOMER routing table has 6 routes, including static and EIGRP routes.
B.The VRF CUSTOMER routing table is empty.
C.The VRF CUSTOMER has only connected routes.
D.The VRF CUSTOMER routing table has an error due to overlapping subnets.
AnswerA

The summary lists route sources and counts: 2 connected, 1 static and 3 EIGRP (internal) networks, giving a Total of 6 routes in the CUSTOMER VRF table. This confirms the VRF holds six routes across those protocols.

Why this answer

The output shows the VRF CUSTOMER routing table summary, listing 2 connected routes, 1 static route, and 3 EIGRP routes, totaling 6 routes. This confirms that the VRF contains routes from multiple sources, including static and EIGRP, making option A correct.

Exam trap

Cisco often tests the ability to interpret the 'summary' keyword output, where candidates may mistakenly think the table is empty or only contains connected routes if they overlook the route source breakdown.

How to eliminate wrong answers

Option B is wrong because the output clearly shows 6 routes, not an empty table. Option C is wrong because the table includes static and EIGRP routes in addition to connected routes. Option D is wrong because there is no indication of overlapping subnets or errors; the summary simply lists route counts without any error messages.

218
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip policy Interface Route-map GigabitEthernet0/1 PBR-MAP R1# show route-map PBR-MAP route-map PBR-MAP, permit, sequence 10 Match clauses: ip address (access-lists): 101 Set clauses: ip next-hop verify-availability 10.1.1.2 10 track 1 Policy routing matches: 150 packets, 12000 bytes R1# show track 1 Track 1 IP SLA 1 reachability Reachability is Down 1 change, last change 00:05:20 Latest operation return code: timeout Tracked by: ROUTE-MAP 0 Based on this output, what is the most likely outcome?

A.Packets matching ACL 101 are forwarded to 10.1.1.2 regardless.
B.Packets matching ACL 101 are dropped.
C.Packets matching ACL 101 are routed normally via the routing table.
D.The route map is removed from the interface due to the track failure.
AnswerC

The route-map's set clause uses next-hop verify-availability with track 1, and track 1 is Down because IP SLA 1 timed out. With the tracked next hop unavailable, the policy route fails and packets matching ACL 101 fall through to normal destination-based routing.

Why this answer

The route map uses 'ip next-hop verify-availability' with tracking. Track 1 is down because IP SLA 1 reports unreachability. Therefore, the set clause will not be applied, and packets matching ACL 101 will not be forwarded to 10.1.1.2; they will be routed normally via the routing table.

219
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate SSH users against an external TACACS+ server. The TACACS+ server is reachable at 10.10.10.5, and the shared secret is 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, a local user account 'backup' with privilege level 15 is used for authentication. Which configuration sequence correctly achieves this?

A.aaa new-model aaa authentication login default group tacacs+ username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
B.aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 password Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
C.aaa new-model aaa authentication login default group tacacs+ enable username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
D.aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
AnswerD

This configuration enables AAA, sets the default login authentication method list to try TACACS+ first and then fall back to the local database, creates a local user with privilege 15, and defines the TACACS+ server with its IP and key. This exactly meets the requirement of using TACACS+ with local fallback and a local privileged account.

Why this answer

The correct configuration must enable AAA, set the default login authentication to use TACACS+ first and then the local database, create a local user with privilege 15, and define the TACACS+ server with the correct IP and key. The fallback to local is essential for when the TACACS+ server is unreachable, and using 'secret' is best practice for storing the local password securely.

Exam trap

The trap here is assuming that simply creating a local user account is enough for fallback, but the AAA method list must explicitly include 'local' after the TACACS+ group to enable fallback.

220
MCQmedium

A network engineer runs the following command to verify BFD with EIGRP: R1# show ip eigrp 100 topology 10.2.2.0/24 EIGRP-IPv4 Topology Entry for AS(100)/ID(10.2.2.0/24) State: Passive, Query origin flag: 1, 1 Successor(s), FD is 131072 Descriptor Blocks: 10.1.1.2 (GigabitEthernet0/0), from 10.1.1.2, Send flag: 0x0 Composite metric: (131072/130816), Route is Internal Vector metric: Minimum bandwidth is 100000 Kbit Total delay is 100 microseconds Reliability is 255/255 Load is 1/255 Minimum MTU is 1500 Hop count is 1 Originating router is 2.2.2.2 BFD enabled, BFD state: UP What does this output indicate?

A.EIGRP is using BFD with state UP, providing sub-second convergence.
B.EIGRP has no BFD session for this neighbor.
C.BFD is down, so EIGRP relies on its own hello/dead timers.
D.EIGRP is using BFD in passive mode only.
AnswerA

The topology entry shows BFD enabled with state UP on the successor path via GigabitEthernet0/0. Because BFD detects link failure in milliseconds rather than waiting for EIGRP hold timers, the adjacency is torn down faster, delivering the sub-second convergence described.

Why this answer

The output shows that BFD is enabled for the EIGRP neighbor and the BFD state is UP, indicating fast failure detection is active for this route.

221
MCQmedium

Consider the following partial configuration on router R6: router bgp 65001 bgp router-id 6.6.6.6 neighbor 10.0.0.2 remote-as 65002 neighbor 10.0.0.2 route-map SET-MED out ! route-map SET-MED permit 10 set metric 50 What is the effect of this configuration?

A.Only routes that match a specific prefix will have MED set to 50; other routes will not be advertised.
B.The route-map will set the MED to 50 for all routes advertised to neighbor 10.0.0.2, and all routes will be advertised.
C.The configuration is invalid because the route-map must have a match clause.
D.The MED will only be set if the neighbor is also configured with a route-map for inbound updates.
AnswerB

The outbound route-map applies to every route advertised to 10.0.0.2, and permit sequence 10 has no match clause, so all routes match it. The `set metric 50` action then stamps MED 50 on each advertisement, satisfying the stem's requirement to influence inbound path selection on the neighbouring autonomous system.

Why this answer

The route-map SET-MED is applied as an outbound route-map on the BGP neighbor 10.0.0.2. Since the route-map has a permit statement with no match clause, it implicitly matches all routes. The set metric 50 command then sets the MED (Multi-Exit Discriminator) to 50 for all routes advertised to that neighbor.

All routes are still advertised because the route-map does not contain any deny statements or match conditions that would filter them.

Exam trap

The trap here is that candidates often assume a route-map must have a match clause to be valid, but Cisco permits a route-map with only a set clause, which then applies to all routes matched by the permit statement.

How to eliminate wrong answers

Option A is wrong because the route-map has no match clause, so it matches all routes, not just a specific prefix; also, all routes are advertised, not withheld. Option C is wrong because a route-map does not require a match clause; a permit statement without match conditions matches everything, making the configuration valid. Option D is wrong because the MED is set by the outbound route-map on R6, and no inbound route-map on the neighbor is required for the MED to be set; the neighbor's inbound policy is irrelevant to the outbound set action.

222
MCQmedium

Consider the following BGP configuration on router R2: router bgp 65002 bgp router-id 2.2.2.2 neighbor 10.2.2.1 remote-as 65001 neighbor 10.2.2.1 route-map FILTER in ! route-map FILTER deny 10 match ip address prefix-list BLOCKED ! route-map FILTER permit 20 ! ip prefix-list BLOCKED permit 10.0.0.0/8 le 32 Which statement is true about routes received from 10.2.2.1?

A.All routes are accepted because the deny statement is misconfigured.
B.Routes with prefix 10.0.0.0/8 or more specific are denied; all others are permitted.
C.Only routes exactly matching 10.0.0.0/8 are denied; other 10.x.x.x routes are permitted.
D.The route-map is applied outbound, so it affects routes sent to 10.2.2.1.
AnswerB

The prefix-list matches 10.0.0.0/8 with le 32, covering the /8 itself and every more-specific subnet within it. Route-map sequence 10 denies those matches, while sequence 20 permits everything else, so only 10.0.0.0/8-derived prefixes are filtered.

Why this answer

The prefix-list BLOCKED uses 'permit 10.0.0.0/8 le 32', which matches the 10.0.0.0/8 network and any more specific prefix (up to /32) within that range. The route-map FILTER denies any route matching this prefix-list in sequence 10, and permits all other routes in sequence 20. Since the route-map is applied inbound on neighbor 10.2.2.1, routes from that neighbor matching 10.0.0.0/8 or more specific are denied, while all other routes are accepted.

Exam trap

The trap here is confusing the effect of 'le' in prefix-lists: many candidates assume that '10.0.0.0/8 le 32' only matches the exact /8 prefix, but it actually matches all more specific prefixes as well. Another common mistake is misreading the route-map direction ('in' vs 'out').

How to eliminate wrong answers

Option A is wrong because the deny statement is correctly configured: the prefix-list matches the intended prefixes, and the route-map sequence 10 denies them. Option C is wrong because the 'le 32' parameter expands the match to include all more specific prefixes (e.g., 10.1.0.0/16, 10.1.1.0/24), not just the exact /8. Option D is wrong because the route-map is applied with the 'in' keyword, meaning it filters routes received from the neighbor, not routes sent to it.

223
MCQmedium

Which SNMP version introduced the use of a User-based Security Model (USM) and View-based Access Control Model (VACM)?

A.SNMPv1
B.SNMPv2c
C.SNMPv3
D.SNMPv2u
AnswerC

SNMPv3 added the User-based Security Model for authentication and encryption plus the View-based Access Control Model for granular access, neither of which exists in SNMPv1 or v2c. That cryptographic and access-control architecture is the defining change.

Why this answer

SNMPv3 introduced the User-based Security Model (USM) for authentication and encryption, and the View-based Access Control Model (VACM) for granular access control. These models provide message integrity, authentication, and encryption, addressing the security deficiencies of earlier SNMP versions.

Exam trap

Cisco often tests the distinction between SNMPv2u (which introduced user-based security but not VACM) and SNMPv3 (which combined USM and VACM), leading candidates to mistakenly select SNMPv2u as the version that introduced both models.

How to eliminate wrong answers

Option A is wrong because SNMPv1 uses community strings for authentication with no security model like USM or VACM. Option B is wrong because SNMPv2c also relies on community strings and lacks USM and VACM, despite being an enhanced version of SNMPv2. Option D is wrong because SNMPv2u was an experimental version that introduced user-based security but did not include VACM; it was a precursor to SNMPv3's USM and VACM.

224
MCQhard

An engineer is troubleshooting a BGP peering problem between two routers, R1 (AS 65001) and R2 (AS 65002), connected via a firewall. The BGP session is flapping every few seconds. The engineer notices that the TCP connection is established, but BGP OPEN messages are not exchanged. The firewall logs show that TCP port 179 is allowed, but packets with the BGP marker (0xFFFFFFFF) are being dropped. What is the most likely cause?

A.The firewall is dropping BGP packets because the BGP marker (0xFFFFFFFF) is being flagged as a potential attack or malformed packet.
B.The BGP session is flapping because the keepalive timer is set too low on both routers.
C.The BGP session is flapping because the routers have mismatched BGP AS numbers.
D.The BGP session is flapping because the firewall is performing TCP sequence number randomization, breaking the BGP session.
AnswerA

Some firewalls with BGP inspection or anomaly detection treat the all-ones 16-byte marker as suspicious, dropping the packet even though TCP/179 is permitted. Because the marker fails validation, the OPEN message never reaches the peer, so the session resets repeatedly.

Why this answer

BGP uses a 16-byte marker (all 0xFF) in its messages. Some firewalls or intrusion prevention systems may misinterpret this as a malformed packet and drop it, preventing BGP from establishing.

225
Multi-Selecthard

Which TWO statements about the 'show ip bgp vpnv4 vrf <vrf-name>' command output are correct? (Choose TWO.)

Select 2 answers
A.The output displays only routes that are locally originated by the PE router.
B.The output includes the Route Distinguisher (RD) for each prefix.
C.The output shows the MPLS label assigned to each route.
D.The output is equivalent to 'show ip route vrf <vrf-name>'.
E.The output provides the CEF forwarding information for each prefix.
AnswersB, C

The command displays the VPNv4 table for the specified VRF, and each prefix entry is preceded by its Route Distinguisher, satisfying the requirement to identify per-VRF routes. The RD, in the form ASN:nn or IP:nn, makes otherwise identical customer prefixes unique within the BGP table, so the output necessarily includes it.

Why this answer

Option B is correct because the 'show ip bgp vpnv4 vrf <vrf-name>' output lists each VPNv4 prefix together with its Route Distinguisher (RD), which is prepended to the IPv4 prefix to make it unique within the BGP table. Option C is correct because the same output includes the MPLS label (the VPN label or inner label) associated with each route, which the PE router uses for label-based forwarding of VPN traffic. Option A is incorrect because the command shows all VPNv4 routes in the VRF's BGP table, including routes learned from other PEs via MP-BGP, not just locally originated ones.

Option D is incorrect because 'show ip route vrf <vrf-name>' displays the VRF's IP routing table (RIB), not the BGP VPNv4 table with RDs and labels. Option E is incorrect because CEF forwarding information is shown by commands such as 'show ip cef vrf <vrf-name>', not by the BGP VPNv4 table command.

Exam trap

300-410 often tests the confusion between the BGP VPNv4 table and the VRF IP routing table, causing candidates to assume 'show ip bgp vpnv4 vrf' is equivalent to 'show ip route vrf'.

Page 2

Page 3 of 19

Page 4